Sun Solaris Format(1M) Buffer Overflow Vulnerability
BID:19657
CVE-2006-4319 |Info
Sun Solaris Format(1M) Buffer Overflow Vulnerability
| Bugtraq ID: | 19657 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4319 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 21 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc |
| Not Vulnerable: | |
Discussion
Sun Solaris Format(1M) Buffer Overflow Vulnerability
The format command in Solaris is prone to a buffer-overflow execution vulnerability.
This issue occurs because the application fails to check the size of the data before copying it into a finite-sized buffer.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.
The format command in Solaris is prone to a buffer-overflow execution vulnerability.
This issue occurs because the application fails to check the size of the data before copying it into a finite-sized buffer.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.
Exploit / POC
Sun Solaris Format(1M) Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sun Solaris Format(1M) Buffer Overflow Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
References
Sun Solaris Format(1M) Buffer Overflow Vulnerability
References:
References:
- Security Vulnerability Due to Buffer Overflow in The format(1M) Command May Allo (Sun Microsystems)
- Solaris Homepage (Sun Microsystems)