Secunia Advisory SA28931Sun Solaris 10 Language Input Methods Security Issue
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A security issue has been reported in Sun Solaris, which can be exploited by malicious, local users to modify certain files or directories. The problem is that the Simplified Chinese, Traditional Chinese, Korean and Thai language input methods create world writable or readable files and directories (e.g. ".iiim/le" and ".Xlocale") in a user's home directory. This can be exploited to e.g. modify files and directories in another user's home directory. The security issue affects the following versions: * Solaris 10 for the SPARC platform without patch 120412-08 and patch 120414-20 * Solaris 10 for the x86 platform without patch 120413-08 and patch 120415-20 Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||
205 views | ![]() |
| Limny Multiple Vulnerabilities | |
295 views | ![]() |
| Ubuntu update for thunderbird | |
219 views | ![]() |
| Debian update for php5 | |