Solaris power management 漏洞

Solaris power management 漏洞

漏洞ID 1105372 漏洞类型 其他
发布时间 1998-07-16 更新时间 2005-05-02
图片[1]-Solaris power management 漏洞-安全小百科CVE编号 CVE-1999-1432
图片[2]-Solaris power management 漏洞-安全小百科CNNVD-ID CNNVD-199807-018
漏洞平台 Solaris CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/19126
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199807-018
|漏洞详情
Solaris2.4到2.6版本的电源管理直到系统暂停结束才启动xlock进程,在系统恢复后的短期内,具有物理访问权限的攻击者利用该漏洞从键盘输入字符到最后一个活动的应用程序,这可能获取更多的特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/160/info

A vulnerability exists in Sun's power management software under Solaris versions 2.4-2.6 (although only 2.6 as part of the main distribution). The sys-suspend program is initiated when a user runs the program, or presses the power key on a sun keyboard. This program moves the contents of memory to the disk, and powers down the system. As part of this shutdown procedure, it runs xlock to prevent a user from resuming the machine and accessing the logged in account.

The vulnerability that exists is due to the order in which sys-suspend performs its operations. As xlock is run by this program, it executes after the suspension begins. Upon a resume, there is a window of time during which any data typed at the keyboard is passed to whatever X application last had focus. If this was an xterm, arbitrary commands can be issued. In the even the user who was logged in was root, system security can be entirely subverted.

1: press the power key on Sun keyboard, and suspend the machine. 2: Upon pressing the power button again, the machine will indicate it is resuming, and the screen will go blank. Any data typed between this notification and the resumption of the machine (and xlock) will be passed to the application which last had focus.
|参考资料

来源:BUGTRAQ
名称:19980716SecurityriskwithpowermanagemnetonSolaris2.6
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=90221104525997&w;=2
来源:BID
名称:160
链接:http://www.securityfocus.com/bid/160

相关推荐: Easy Chat Server chat.ghp跨站脚本攻击(XSS)漏洞

Easy Chat Server chat.ghp跨站脚本攻击(XSS)漏洞 漏洞ID 1200487 漏洞类型 跨站脚本 发布时间 2004-12-31 更新时间 2004-12-31 CVE编号 CVE-2004-2465 CNNVD-ID CNNVD-2…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享