CVE-2005-2072

The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:sun:solaris:8.0:*:x86:*:*:*:*:*
cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:solaris:9.0:*:x86:*:*:*:*:*
cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*

History

20 Nov 2024, 23:58

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034730.html - Exploit () http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034730.html - Exploit
References () http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034731.html - Exploit () http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034731.html - Exploit
References () http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034738.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034738.html -
References () http://secunia.com/advisories/15841 - Vendor Advisory () http://secunia.com/advisories/15841 - Vendor Advisory
References () http://securitytracker.com/id?1014537 - () http://securitytracker.com/id?1014537 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-101794-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-101794-1 -
References () http://www.opensolaris.org/jive/thread.jspa?messageID=3497 - () http://www.opensolaris.org/jive/thread.jspa?messageID=3497 -
References () http://www.securityfocus.com/bid/14074 - Exploit () http://www.securityfocus.com/bid/14074 - Exploit
References () http://www.vupen.com/english/advisories/2005/0908 - Vendor Advisory () http://www.vupen.com/english/advisories/2005/0908 - Vendor Advisory

Information

Published : 2005-06-29 04:00

Updated : 2024-11-20 23:58


NVD link : CVE-2005-2072

Mitre link : CVE-2005-2072

CVE.ORG link : CVE-2005-2072


JSON object : View

Products Affected

sun

  • solaris
  • sunos
CWE
CWE-264

Permissions, Privileges, and Access Controls