Product: Solaris 7 Operating System, Solaris 8 Operating System

A security vulnerability in the multilanguage environment library, "libmle" (shipped with the Japanese locale) may allow a local unprivileged user to be able to execute arbitrary code or commands with elevated privileges. The code or commands executed by the user would run with the privileges of the application dynamically linked to the libmle library.

Avoidance: Patch, Workaround
State: Resolved
First released: 25-Jul-2005
Permalink | Comments [0]

Product: Solaris 9 Operating System, Solaris 10 Operating System

The Solaris 9 and Solaris 10 FTP Server, in.ftpd(1M), is based on WU-FTPD (Washington University ftpd) and are affected by a security vulnerability in the "wu_fnmatch" function which may allow a local or remote unprivileged user the ability to cause a Denial of Service (DoS) by consuming a large amount of CPU resources.

Additional information on this issue can be found in the following documents:

Avoidance: Patch, Workaround
State: Resolved
First released: 20-May-2005
Permalink | Comments [0]