Solaris libsldap Buffer Overflow Vulnerability
BID:2931
Info
Solaris libsldap Buffer Overflow Vulnerability
| Bugtraq ID: | 2931 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 26 2001 12:00AM |
| Updated: | Jun 26 2001 12:00AM |
| Credit: | Discovered by Jouko Pynnönen <[email protected]>. |
| Vulnerable: |
Sun Solaris 8_x86 Sun Solaris 8_sparc |
| Not Vulnerable: | |
Discussion
Solaris libsldap Buffer Overflow Vulnerability
Solaris 8 ships with a shared library that implements LDAP functionality called 'libsldap'. This library is linked to by a number of system utilities, many of them installed setuid or setgid.
Libsldap contains a buffer overflow vulnerability in it's handling of the 'LDAP_OPTIONS' environment variable.
Local attackers can exploit this vulnerability in setuid/setgid programs linked to libsldap to elevate privileges.
Solaris 8 ships with a shared library that implements LDAP functionality called 'libsldap'. This library is linked to by a number of system utilities, many of them installed setuid or setgid.
Libsldap contains a buffer overflow vulnerability in it's handling of the 'LDAP_OPTIONS' environment variable.
Local attackers can exploit this vulnerability in setuid/setgid programs linked to libsldap to elevate privileges.
Solution / Fix
Solaris libsldap Buffer Overflow Vulnerability
Solution:
Sun has released fixes for Sparc and x86 versions of Solaris.
Sun Solaris 8_x86
Sun Solaris 8_sparc
Solution:
Sun has released fixes for Sparc and x86 versions of Solaris.
Sun Solaris 8_x86
Sun Solaris 8_sparc
-
Sun 108993-13
http://sunsolve.sun.com
References
Solaris libsldap Buffer Overflow Vulnerability
References:
References:
- Solaris LIBSLDAP Local Exploit (CORE Security)
- Solaris LIBSLDAP Local Exploit (CORE Security)
- Sunsolve Online(tm) (Sun Microsystems)