Solaris Flaw Opens Door for Hackers

執筆者
Dennis Fisher
Dennis Fisher
Published: Jan 22, 2003
Updated: Feb 2, 2021
1 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

There is a serious vulnerability in several versions of the popular Solaris operating system that enables a remote attacker to access any file and obtain root privileges on a vulnerable machine.

The flaw affects Sun Microsystems Inc.s Solaris 2.5.1, 2.6, 7, 8 and 9 running on Sparc-based or Intel Corp.-based servers.

The vulnerability lies in a library service daemon known as the Kodak Color Management System. KCMS is a framework for developing color-management systems. The KCMS server is used to enable library functions to access profiles on remote machines. However, thanks to a directory traversal condition in one of the servers procedures, an attacker could retrieve any file on the vulnerable system.

Specifically, the KCS_OPEN_PROFILE procedure is vulnerable to this attack, according to an advisory on the flaw released Wednesday by Entercept Security Technologies, the San Jose, Calif., company that discovered the problem. The CERT Coordination Center plans to release a vulnerability note on the issue on Wednesday.

Because the KCMS server runs with root privileges, an attacker who is able to exploit this vulnerability would have complete control of the machine and could access any file of choice.

Sun, based in Santa Clara, Calif., will release a patch for the vulnerability on Wednesday.

Dennis Fisher

Dennis Fisher

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。