Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files. http://sunsolve.sun.com/search/document.do?assetkey1-26-248646-1
This issue can occur in the following releases:
SPARC Platform
* Sun SNMP Management Agent "SUNWmasf" 1.4u2 thru 1.5.4 (For Solaris 8, 9 and 10)
http://sunsolve.sun.com/search/document.do?assetkey1-26-248646-1
This issue is addressed in the following release:
SPARC Platform
* Sun SNMP Management Agent ("SUNWmasf") 1.5.5 or later (For Solaris 8, 9 and 10)
Sun SNMP Management Agent is available for download at http://www.sun.com/download/
Publication date: Mon, 29 Dec 2008 21:24:00 +0000