CDE dtsession Buffer Overflow Vulnerability
BID:2603
Info
CDE dtsession Buffer Overflow Vulnerability
| Bugtraq ID: | 2603 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0426 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 11 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was revealed in an advisory posted to BugTraq by LSD <[email protected]> on 11 April 2001. |
| Vulnerable: |
Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 |
| Not Vulnerable: | |
Discussion
CDE dtsession Buffer Overflow Vulnerability
The CDE Session Manager 'dtsession' is vulnerable to a buffer overflow that could yield root privileges to an attacker.
The bug exists in dtsession's LANG environment variable parser. If an overly long LANG variable is set and dtsession is subsequently run, dtsession will overflow. Because the dtsession binary is setuid root, the overflow allows an attacker to execute arbitrary code as root.
An exploit is available against x86 Solaris installations of CDE.
The CDE Session Manager 'dtsession' is vulnerable to a buffer overflow that could yield root privileges to an attacker.
The bug exists in dtsession's LANG environment variable parser. If an overly long LANG variable is set and dtsession is subsequently run, dtsession will overflow. Because the dtsession binary is setuid root, the overflow allows an attacker to execute arbitrary code as root.
An exploit is available against x86 Solaris installations of CDE.
Exploit / POC
CDE dtsession Buffer Overflow Vulnerability
An exploit is available against x86 Solaris installations of CDE.
An exploit is available against x86 Solaris installations of CDE.
Solution / Fix
CDE dtsession Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue.
If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10 m
SGI IRIX 6.5.11
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13
SGI IRIX 6.5.14
SGI IRIX 6.5.2
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.3
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.6
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue.
If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10 m
SGI IRIX 6.5.11
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13
SGI IRIX 6.5.14
SGI IRIX 6.5.2
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.3
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.6
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9
References
CDE dtsession Buffer Overflow Vulnerability
References:
References:
- /usr/dt/bin/dtsession (lsd-pl.net)
- Solaris[tm] CDE (Common Desktop Environment) (Sun Microsystems)