|
![]() ![]() |
CERT® Advisory CA-1995-12 Sun 4.1.X Loadmodule VulnerabilityOriginal issue date: October 18, 1995Last revised: September 23, 1997 Attached copyright statement A complete revision history is at the end of this file. The CERT Coordination Center has received reports of problems with the loadmodule(8) program. An exploitation script is available and has been used by local users to gain root privileges. The problem is present in SunOS 4.1.X only, and there is a patch available for sun4 architectures. The CERT staff recommends that you install the appropriate patch as soon as possible and take the steps in Section III.B. to further protect your system. We will update this advisory as we receive additional information. Please check advisory files regularly for updates that relate to your site.
I. DescriptionThe loadmodule(8) program is used by the xnews(1) window system server to load two dynamically loadable kernel drivers into the currently running system and to create special devices in the /dev directory to use those modules. These modules and special files are used to provide a SunView binary compatibility mode while running the X11/NeWS windowing system. Because of the way the loadmodule(8) program sanitizes its environment, unauthorized users can gain root access on the local machine. A script is publicly available and has been used to exploit this vulnerability. This problem is present in SunOS 4.1.X only.
II. ImpactLocal users can gain root privileges.
III. SolutionThe CERT staff recommends that you take the steps described in both A and B below.
A. Obtain and install the appropriate patches according to the instructions included with the patches.Patches are available through your local Sun Answer Center and by FTP from ftp://sunsolve1.sun.com/pub/patches/100448-03.tar.Z
Module Patch ID Filename
---------- --------- ---------------
loadmodule 100448-03 100448-03.tar.Z
Checksum:
MD5 (100448-03.tar.Z) = 183a22f0a2f6020f1389b6aeea5ca6c6
B. Because, in general, a set-user-id program can lead to security exposures, you should also do at least step 1 below. We recommend doing steps 2 and 3 as well.The intent of these directions is make the loadmodule(8) program work only for the super-user (currently it works for all users because it is set-user-id) and to execute it each time the system boots. By following these directions, users who require SunView binary compatibility will have it available to them.
The CERT Coordination Center staff thanks Wolfgang Ley and Sun Microsystems for their support in the development of this advisory. This document is available from: http://www.cert.org/advisories/CA-1995-12.html CERT/CC Contact Information
Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryptionWe strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from If you prefer to use DES, please call the CERT hotline for more information. Getting security informationCERT publications and other security information are available from our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY Conditions for use, disclaimers, and sponsorship information
Copyright 1995, 1996 Carnegie Mellon University. Revision History
Sep. 23, 1997 Updated copyright statement
Aug. 30, 1996 References to README files were removed because updates are
added to the advisories themselves.
|








