Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/208 | vdb entry patch vendor advisory |
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/145 | patch vendor advisory |