Product: Sun Cluster 3.1

A local user who has been granted the "solaris.cluster.gui" authorization may be able to view files which would normally be inaccessible to that user due to a security vulnerability in the Sun Cluster SunPlex Manager GUI.

Avoidance: Upgrade
State: Resolved
First released: 29-Mar-2006
Permalink | Comments [0]

Product: Solaris 10 Operating System

The Xorg X server (see Xorg(1)) is one of the X Window System display servers available on the Solaris x86 platform. A local unprivileged user may be able to create or overwrite any file on the system or execute arbitrary code with elevated privileges due to several security vulnerabilities found in the Xorg X server.

Sun acknowledges, with thanks, the X.Org Foundation for bringing these issues to our attention. Sun also thanks Coverity for donating their 'Coverity Prevent' product to the X.Org Foundation which uncovered these issues.

These issues are referenced in the following document:

CVE-2006-0745 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0745

Avoidance: Workaround, Patch
State: Resolved
First released: 20-Mar-2006
Permalink | Comments [0]

Product: Solaris 9 Operating System, Solaris 10 Operating System, Solaris 8 Operating System

A local unprivileged user may be able to cause significant performance degradation, hang the system, or panic the system, resulting in a Denial of Service (DoS) condition. This is due to a security vulnerability involving the pagedata subsystem of the process file system "/proc" (see proc(4)).

Avoidance: Patch
State: Resolved
First released: 03-Mar-2006
Permalink | Comments [0]

Product: Sun N1 Grid Engine 6, Sun Grid Engine 5.3

A security vulnerability in the Sun Grid Engine 5.3/N1 Grid Engine 6.0 rsh(1) binary may allow a local unprivileged user the ability to gain unauthorized root access.

Avoidance: Patch
State: Resolved
First released: 27-Mar-2006
Permalink | Comments [0]

Product: Solaris 9 Operating System, Solaris 8 Operating System

A security vulnerability in the "/usr/ucb/ps" (see ps(1B)) command may allow unprivileged local users the ability to see environment variables and their values for processes which belong to other users.

Avoidance: Patch, Workaround
State: Resolved
First released: 27-Mar-2006
Permalink | Comments [0]

Product: Solaris 9 Operating System, Solaris 8 Operating System

Security vulnerabilities in "Safe.pm" and "CGI.pm" Perl modules may allow the following:

1. The "Safe.pm" Perl module contains a security vulnerability which may allow a local or remote unprivileged user to bypass compartment access controls if a Perl application utilizes the "Safe.pm" Perl module.

2. The "CGI.pm" Perl module contains a cross site scripting security vulnerability, see the following URLs for details about cross site scripting and web script vulnerabilities:

Due to this "CGI.pm" cross site scripting vulnerability users may unintentionally execute scripts in their browser written by a remote unprivileged user if they follow untrusted links/URIs in web pages, mail messages, or newsgroup postings. By following these untrusted links/URIs, the remote attacker may be able to execute commands with the privileges of the user who accessed the link/URI.

These issues are described here:

Avoidance: Workaround, Patch
State: Resolved
First released: 23-Jan-2004
Permalink | Comments [0]

Product: GNOME 2.0 Desktop, Sun Java Desktop System 2003

Due to multiple security vulnerabilities in the libgdk_pixbuf library, a remote unprivileged user may be able to execute arbitrary code with the privileges of a local user when that local user has loaded an XPixmap (Xpm) format image file supplied by an untrusted user.

The libgdk_pixbuf library is part of the GIMP Toolkit (GTK+) and is used for loading and rendering images.

These issues are described in the following documents:

Avoidance: Patch, Workaround
State: Resolved
First released: 23-Jun-2005
Permalink | Comments [0]