CDE LibDTHelp LOGNAME Environment Variable Local Buffer Overflow Vulnerability
BID:11050
Info
CDE LibDTHelp LOGNAME Environment Variable Local Buffer Overflow Vulnerability
| Bugtraq ID: | 11050 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 2004 12:00AM |
| Updated: | Aug 25 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to iDEFENSE Labs. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 |
| Not Vulnerable: | |
Discussion
CDE LibDTHelp LOGNAME Environment Variable Local Buffer Overflow Vulnerability
A buffer overflow vulnerability is identified in CDE libDtHelp. Because of this, it may be possible for a local attacker to gain elevated privileges.
The problem is in the handling of data contained in a certain environment variable. Due to insufficient bounds checking, it is possible that system memory will be corrupted potentially overwriting sensitive values when the environment variable data is copied into memory.
A local attacker may exploit this vulnerability in order to execute arbitrary code in the context software that is linked to the vulnerable library.
A buffer overflow vulnerability is identified in CDE libDtHelp. Because of this, it may be possible for a local attacker to gain elevated privileges.
The problem is in the handling of data contained in a certain environment variable. Due to insufficient bounds checking, it is possible that system memory will be corrupted potentially overwriting sensitive values when the environment variable data is copied into memory.
A local attacker may exploit this vulnerability in order to execute arbitrary code in the context software that is linked to the vulnerable library.
Exploit / POC
CDE LibDTHelp LOGNAME Environment Variable Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CDE LibDTHelp LOGNAME Environment Variable Local Buffer Overflow Vulnerability
Solution:
Other vendors have released fixes to address the issue described in BID 8973. It is not known whether these fixes also address the issue described in this BID.
Sun has released Alert ID 57414 with patches to address the issue described in BID 8973, these patches also address this issue.
Sun Solaris 7.0_x86
Sun Solaris 9_x86
Sun Solaris 7.0
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 9
Solution:
Other vendors have released fixes to address the issue described in BID 8973. It is not known whether these fixes also address the issue described in this BID.
Sun has released Alert ID 57414 with patches to address the issue described in BID 8973, these patches also address this issue.
Sun Solaris 7.0_x86
Sun Solaris 9_x86
Sun Solaris 7.0
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 9
References
CDE LibDTHelp LOGNAME Environment Variable Local Buffer Overflow Vulnerability
References:
References:
- CDE libDtHelp LOGNAME Buffer Overflow Vulnerability (iDEFENSE)
- Sun Alert ID: 57414 (Sun Microsystems)