|
Solaris priocntl() System Call Local Root Vulnerability
A directory traversal vulnerability has been discovered in priocntl() when accessing a module. It has been reported that priocntl() fails to sanitize module names specified in the pc_clname buffer. By supplying the function with a module name prepended with dot-dot-slash sequences (../), it is possible to load a module from an arbitrary location. |
|
|
Privacy Statement |