CVE-2008-4131
Solaris 8-10 - Privilege Escalation via Tag Handling in vi ex vedit view and edit
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4131. PoCs published by Eli the Bearded.
AI-analyzed exploit summary This exploit demonstrates a command execution vulnerability in Sun Solaris text editors (vi) by leveraging a maliciously crafted tags file to execute arbitrary commands when a user opens a file with a specific tag.
Description
Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.
Exploits (1)
This exploit demonstrates a command execution vulnerability in Sun Solaris text editors (vi) by leveraging a maliciously crafted tags file to execute arbitrary commands when a user opens a file with a specific tag.