Solaris 7/8 kcms_configure Command-Line Buffer Overflow Vulnerability
BID:2558
Info
Solaris 7/8 kcms_configure Command-Line Buffer Overflow Vulnerability
| Bugtraq ID: | 2558 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 09 2001 12:00AM |
| Updated: | Apr 09 2001 12:00AM |
| Credit: | The vulnerability was discovered by Riley Hassell of eEye <mailto:[email protected]> and made public in a post to BugTraq on 9 Apr, 2001. |
| Vulnerable: |
Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 |
| Not Vulnerable: | |
Discussion
Solaris 7/8 kcms_configure Command-Line Buffer Overflow Vulnerability
The Kodak Color Management System, or KCMS, is a package that ships with workstation installations of Solaris 7 and 8. kcms_configure, a part of KCMS, is vulnerable to a buffer overflow if it is passed an overly long string on the command-line by a local user. kcms_configure is installed setuid root, so a buffer overflow can lead to arbitrary code execution as root.
An exploit for x86 Solaris is available to attackers.
The Kodak Color Management System, or KCMS, is a package that ships with workstation installations of Solaris 7 and 8. kcms_configure, a part of KCMS, is vulnerable to a buffer overflow if it is passed an overly long string on the command-line by a local user. kcms_configure is installed setuid root, so a buffer overflow can lead to arbitrary code execution as root.
An exploit for x86 Solaris is available to attackers.
References
Solaris 7/8 kcms_configure Command-Line Buffer Overflow Vulnerability
References:
References:
- Solaris[tm] Product Line (Sun Microsystems)