Sun Solstice AdminSuite 'sadmind' 'adm_build_path()' Remote Stack Buffer Overflow Vulnerability
BID:31751
Info
Sun Solstice AdminSuite 'sadmind' 'adm_build_path()' Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 31751 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4556 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2008 12:00AM |
| Updated: | Jun 18 2009 09:09PM |
| Credit: | Adriano Lima from RISE Security |
| Vulnerable: |
Sun Solstice AdminSuite 2.2 _x86 Sun Solstice AdminSuite 2.2 Sun Solstice AdminSuite 2.1 _x86 Sun Solstice AdminSuite 2.1 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri CTX 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks CDMA W-NMS-CNM 0 Avaya Interactive Response 2.0 Avaya CMS Server 13.0 Avaya CMS Server 14.1 Avaya CMS Server 14.0 Avaya CMS Server 13.1 |
| Not Vulnerable: | |
Discussion
Sun Solstice AdminSuite 'sadmind' 'adm_build_path()' Remote Stack Buffer Overflow Vulnerability
Sun Solstice AdminSuite is prone to a remote stack-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to execute arbitrary code in the context of the application. Successful exploits will compromise the application and the underlying computer. Failed attacks will cause denial-of-service conditions.
We don't know which specific versions of Solstice AdminSuite are affected, but versions for Solaris 8 and 9 are reported vulnerable. We will update this BID as more information emerges.
Sun Solstice AdminSuite is prone to a remote stack-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to execute arbitrary code in the context of the application. Successful exploits will compromise the application and the underlying computer. Failed attacks will cause denial-of-service conditions.
We don't know which specific versions of Solstice AdminSuite are affected, but versions for Solaris 8 and 9 are reported vulnerable. We will update this BID as more information emerges.
Exploit / POC
Sun Solstice AdminSuite 'sadmind' 'adm_build_path()' Remote Stack Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Solution / Fix
Sun Solstice AdminSuite 'sadmind' 'adm_build_path()' Remote Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Sun Solstice AdminSuite 'sadmind' 'adm_build_path()' Remote Stack Buffer Overflow Vulnerability
References:
References:
- Sun Homepage (Sun Microsystems )
- [RISE-2008001] Sun Solstice AdminSuite sadmind adm_build_path() Buffer Overflow (RISE Security
) - 245806 - A Buffer Overflow Security Vulnerability in the Solaris sadmind(1M) Dae (Sun)
- ASA-2008-448 A Buffer Overflow Security Vulnerability in the Solaris sadmind(1M) (Avaya)
- Nortel Response to Sun Alerts 245806 & 259468 - Solaris 8 & 9 - Vulnerabilities (Nortel Networks)