May 3, 2002 : CERT Finds Security Gap in Sun Solaris


📅 - The CERT Coordination Center at Carnegie Mellon University (cert.org), which provides technical advice and coordinates responses to Internet security issues, said this week it had found a security vulnerability that affects Sun Solaris versions 2.5.1, 2.6, 7, and 8.

The potential security gap is a format string vulnerability in the rwall daemon, a utility that is used to listen for wall requests on a network. The vulnerability could potentially allow hackers to execute code in Solaris. CERT said the vulnerability could be exploited both locally and remotely, "although remote exploitation is significantly more difficult," an advisory from CERT said.
CERT also said that other UNIX-based versions adopted by vendors that include IBM, Hewlett Packard and Compaq were not vulnerable.
According to CERT's advisory, Sun has acknowledged the vulnerability, but has yet to release a patch. "Sun is currently generating patches for this issue and will be releasing a Sun Security Bulletin once the patches are available," the advisory said.

Reads: 1461 | Category: General | Source: TheWHIR : Web Host Industry Reviews
URL source: http://www.thewhir.com/marketwatch/cer050302.cfm
Want to add a website news or press release ? Just do it, it's free! Use add web hosting news!