积极预防 及时发现
快速响应 力保恢复
在 SUN 系统中构造特殊参数能够提升自身权限
发布时间:2001-05-17 信息来源:管理员

涉及程序: syscall 描述: 详细: SUN 发布安全公告,指出其操作系统的 SYSCALL 存在漏洞,并建议用户尽快打上补丁。 攻击者通过构造一个参数能提升自身权限,从而能够访问内核内存中的任意地址。 受影响系统: Intel Platform Edition of Solaris 8, 7, and 2.6 (SunOS 5.8_x86, 5.7_x86, and 5.6_x86). Intel Platform Edition of Trusted Solaris 8 and 7. 不受影响系统: All SPARC Platform Editions of Solaris Intel Platform Editions of Solaris prior to 2.6. 补丁列表: OS Version Patch ID __________ _________ SunOS 5.8_x86 108529-07 SunOS 5.7_x86 106542-16 SunOS 5.6_x86 105182-27 (Scheduled availability June 18, 2001) Trusted Solaris _______________ TS8_x86 110338-02 (available soon) TS7_x86 109597-05 (available soon) 解决方案: 请用户下载安装补丁: http://sunsolve.sun.com/securitypatch (补丁地址) ftp://sunsolve.sun.com/pub/patches/CHECKSUMS (校验和地址)