pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a ? (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Solaris | Sun | 2.6 (including) | 2.6 (including) |
Sunos | Sun | 5.5.1 (including) | 5.5.1 (including) |
Sunos | Sun | 5.7 (including) | 5.7 (including) |
Sunos | Sun | 5.8 (including) | 5.8 (including) |