in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Audit ID: 11957 (Sun Solaris Trusted Extensions Local Privilege Escalation - Solaris 10 SPARC)

Last post 02-08-2010 3:06 PM by cpote. 1 replies.
Page 1 of 1 (2 items)
Sort Posts: Previous Next
  • 02-04-2010 10:50 AM

    • matinau
    • Top 500 Contributor
    • Joined on 02-04-2010
    • Ft. Sam Houston, TX
    • Posts 3

    Audit ID: 11957 (Sun Solaris Trusted Extensions Local Privilege Escalation - Solaris 10 SPARC)

    We believe this to be a false-positive.

    The Retina report states to Apply patch 143502-01 or newer - which we promptly accomplished (and have rebooted).

    # showrev -p |grep 143502
    Patch: 143502-01 Obsoletes:  Requires:  Incompatibles:  Packages: SUNWgnome-base-libs

    Retina is still showing this as a Cat I Finding.

    The details in the report are odd here. It this saying that it tested for packages/patches with the textual name "SUNWGNOME-BASE-LIBS" and only found the patch 125095-15 with that name?  Is Retina not explicitly looking for the patch 143502-01 that it wants installed?!?

    Tested Value:      +(SUNWGNOME-BASE-LIBS)
    Found Value:     PATCH: 125095-15 OBSOLETES: REQUIRES: INCOMPATIBLES: PACKAGES: SUNWOCFD, SUNWCSU, SUNWCSR, SUNWCNETR, SUNWCAR, SUNWCAKR, SUNWKVM, SUNWCKR, SUNWCSD, SUNWTER, SUNWPL5U, SUNWTFTP, SUNWPERL584CORE, SUNWPERL584USR, SUNWESU, SUNWXWDV, SUNWCSLR, SUNWKRBR, S

    If I do a search for all related GNome patches, I get

    # showrev -p|grep -i SUNWGNOME-BASE-LIBS
    Patch: 120460-16 Obsoletes:  Requires:  Incompatibles:  Packages: SUNWgnome-base-libs-root, SUNWgnome-base-libs-share, SUNWgnome-base-libs, SUNWgnome-base-libs-devel-share, SUNWgnome-base-libs-devel
    Patch: 122700-02 Obsoletes:  Requires:  Incompatibles:  Packages: SUNWgnome-base-libs-root
    Patch: 143502-01 Obsoletes:  Requires:  Incompatibles:  Packages: SUNWgnome-base-libs

    Matt M. Morris
    Unix Administrator
    US Army, Ft. Sam Houston TX
  • 02-08-2010 3:06 PM In reply to

    • cpote
    • Top 500 Contributor
    • Joined on 02-01-2010
    • Posts 2

    Re: Audit ID: 11957 (Sun Solaris Trusted Extensions Local Privilege Escalation - Solaris 10 SPARC)

     I believe you are correct!  Somebody fat fingered the entry in the audits.xml file. 

    Search for the ID number of the check, in quotes (i.e. “11957”), in the “audits.xml” file located in Retina’s “database” subdirectory.  Check out the “data” tag.  You can edit it to add the missing close-parenthesis (i.e. change “(143502-([1-9][0-9]|0[1-9])” to “(143502-([1-9][0-9]|0[1-9]))”).  Then rescan.

    I hope that helps (it worked for me).

Page 1 of 1 (2 items)
© 1995 - 2009 eEye Incorporated