Solaris PTExec Buffer Overflow Vulnerability
BID:2898
Info
Solaris PTExec Buffer Overflow Vulnerability
| Bugtraq ID: | 2898 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 21 2001 12:00AM |
| Updated: | Jun 21 2001 12:00AM |
| Credit: | This vulnerability was announced to Bugtraq by Pablo Sor <[email protected]> on June 21, 2001. |
| Vulnerable: |
Sun SunVTS 4.3 Sun SunVTS 4.2 Sun SunVTS 4.1 Sun SunVTS 4.0 |
| Not Vulnerable: | |
Discussion
Solaris PTExec Buffer Overflow Vulnerability
SunVTS is the Sun Validation Test Suite, distributed and maintained by Sun Microsystems. The SunVTS is used to test various components of OEM Sun hardware, and can also be used to stress-test components and sub-components.
A buffer overflow in the -o of the ptexec command exists. It is possible for a local user to overwrite stack memory, including the return address.
This makes it possible for a local user to gain elevated privileges, and potentially full administrative access.
SunVTS is the Sun Validation Test Suite, distributed and maintained by Sun Microsystems. The SunVTS is used to test various components of OEM Sun hardware, and can also be used to stress-test components and sub-components.
A buffer overflow in the -o of the ptexec command exists. It is possible for a local user to overwrite stack memory, including the return address.
This makes it possible for a local user to gain elevated privileges, and potentially full administrative access.
Solution / Fix
Solaris PTExec Buffer Overflow Vulnerability
References
Solaris PTExec Buffer Overflow Vulnerability
References:
References: