Secunia Security Advisory - A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to bypass certain security restrictions.
a4c7b0012a9934ac45df15ae57b3115609bc94a03b4c2bf88e5ad5dd3e420234
----------------------------------------------------------------------
Want a new job?
http://secunia.com/secunia_security_specialist/
http://secunia.com/hardcore_disassembler_and_reverse_engineer/
International Partner Manager - Project Sales in the IT-Security
Industry:
http://corporate.secunia.com/about_secunia/64/
----------------------------------------------------------------------
TITLE:
Sun Solaris Trusted Extensions Labeled Networking Unauthorised Access
SECUNIA ADVISORY ID:
SA31412
VERIFY ADVISORY:
http://secunia.com/advisories/31412/
CRITICAL:
Less critical
IMPACT:
Security Bypass
WHERE:
>From remote
OPERATING SYSTEM:
Sun Solaris 10
http://secunia.com/product/4813/
DESCRIPTION:
A vulnerability has been reported in Sun Solaris, which can be
exploited by malicious people to bypass certain security
restrictions.
The vulnerability is caused due to Solaris Trusted Extensions Labeled
Networking allowing remote unauthorised users from another system (at
the same label) to gain access to the global zone (administrative
zone) of an affected system.
Successful exploitation requires access to a username and password
that is valid within the global zone and that a labeled zone, which
is in the "installed" state exists on the target system.
The vulnerability is reported in Solaris 10 and OpenSolaris systems
which have installed and configured Solaris Trusted Extensions.
SOLUTION:
Apply patches.
-- SPARC Platform --
Solaris 10:
Apply patch 125100-08 or later.
OpenSolaris:
Fixed in build snv_68 or later.
-- x86 Platform --
Solaris 10:
Apply patch 125101-08 or later.
OpenSolaris:
Fixed in builds snv_68 or later.
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-240099-1
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------