Description: A vulnerability has been reported in Solaris, which can be exploited by malicious users to delete files on a vulnerable system.
The vulnerability is caused due to an error in the printd daemon when handling cascaded job requests. This can be exploited to delete arbitrary files from the system with the privileges of the user running the printd daemon via a specially crafted cascaded job request.
NOTE: An exploit for the vulnerability is publicly available.
Solution: Apply patches.
-- SPARC Platform --
Solaris 7:
Apply patch 107115-19 or later.
Solaris 8:
Apply patch 109320-16 or later.
Solaris 9:
Apply patch 113329-15 or later.
Solaris 10:
Apply patch 120467-01 or later.
-- x86 Platform --
Solaris 7:
Appy patch 107116-19 or later.
Solaris 8:
Apply patch 109321-16 or later.
Solaris 9:
Apply patch 114980-16 or later.
Solaris 10:
Apply patch 120468-01 or later.
Provided and/or discovered by: The vendor credits H.D. Moore.
Changelog: 2005-10-20: Updated "Description" and "Original Advisory" sections.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.