English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Sun Solaris Trusted Extensions XScreenSaver Security Bypass


Secunia ID

SA37224

CVE-ID

CVE-2009-3851

Release Date

04 Nov 2009

Last Change

09 Nov 2009

Criticality

Not Critical

Solution Status

Vendor Patch

Where

Local system

Impact
Security Bypass

This covers vulnerabilities or security issues where malicious users or people can bypass certain security mechanisms of the application.

The actual impact varies significantly depending on the design and purpose of the affected application.

Description

A security issue has been reported in Sun Solaris, which can be exploited by malicious people with physical access to the system to potentially bypass certain security restrictions.

The security issue is caused due to the Solaris Trusted Extensions implementation preventing XScreenSaver from running and can be exploited to potentially leave the screen unlocked.

The security issue is reported in Solaris 10 with Solaris Trusted Extensions installed and configured.

Solution

Apply patches.

-- SPARC Platform --

Solaris 10:
Apply patch 120094-28 or later.

-- x86 Platform --

Solaris 10:
Apply patch 120095-28 or later.

Reported by

Reported by the vendor.

Original Advisory

http://sunsolve.sun.com/search/document.do?assetkey=1-66-270809-1