A local or remote user that is able to send packets to the snmpXdmi
daemon on a system may gain root privileges.
Appendix A. - Vendor Information
Sun Microsystems
We can confirm that this affects all versions of Solaris that ship
the SNMP to DMI mapper daemon, that is, Solaris 2.6, 7 and 8. To the
best of my understanding from discussion with the engineering group
working on this, for sites which do use DMI (dmispd) and the mapper
(snmpXdmid), there are no workarounds.
The CERT/CC thanks Job de Haas (job@itsx.com) of ITSX BV Amsterdam,
The Netherlands (http://www.itsx.com) for reporting this vulnerability
to the CERT/CC.
This document was written by Brian B. King with significant contributions by Jeff Havrilla, and Cory F. Cohen.
This document is available from:
CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4)
Monday through Friday; they are on call for emergencies during other
hours, on U.S. holidays, and on weekends.
We strongly urge you to encrypt sensitive information sent by
email. Our public PGP key is available from
If you prefer to use DES, please call the CERT hotline for more
information.
CERT publications and other security information are available from
our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
Copyright 2001 Carnegie Mellon University.