Solaris whodo Buffer Overflow Vulnerability
BID:2935
Info
Solaris whodo Buffer Overflow Vulnerability
| Bugtraq ID: | 2935 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1076 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 05 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Discovered by Pablo Sor <[email protected]>. |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.5 |
| Not Vulnerable: | |
Discussion
Solaris whodo Buffer Overflow Vulnerability
The 'whodo' utility shipped with Sun Microsystems' Solaris provides a listing of users online and their activities. It is installed setuid root because it reads from the 'utmp' log as well as from the process table.
'whodo' contains a buffer overflow which can be exploited to gain root privileges.
The 'whodo' utility shipped with Sun Microsystems' Solaris provides a listing of users online and their activities. It is installed setuid root because it reads from the 'utmp' log as well as from the process table.
'whodo' contains a buffer overflow which can be exploited to gain root privileges.
Exploit / POC
Solaris whodo Buffer Overflow Vulnerability
An exploit written by Pablo Sor <[email protected]> is available:
An exploit written by Pablo Sor <[email protected]> is available: