Solaris LBXProxy Display Name Buffer Overflow Vulnerability
BID:4633
Info
Solaris LBXProxy Display Name Buffer Overflow Vulnerability
| Bugtraq ID: | 4633 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0090 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 29 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovery of this issue is credited to Kevin Kotas of the eSecurityOnline Research and Development Team. |
| Vulnerable: |
Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 |
| Not Vulnerable: | |
Discussion
Solaris LBXProxy Display Name Buffer Overflow Vulnerability
Low-Bandwidth X Proxy (lbxproxy) is a server that handles low-bandwidth connections to X Windows. It runs on Solaris as well as a number of Unix and Linux variants.
lbxproxy is prone to a locally exploitable buffer overflow condition. This is due to insufficient bounds checking of the display name command line option.
Successful exploitation will enable an attacker to execute arbitrary attacker-supplied instructions and as a consequence gain elevated privileges.
This issue was reported for lbxproxy on the Sun Solaris operating system. It is not known whether this is an issue on other operating systems.
Low-Bandwidth X Proxy (lbxproxy) is a server that handles low-bandwidth connections to X Windows. It runs on Solaris as well as a number of Unix and Linux variants.
lbxproxy is prone to a locally exploitable buffer overflow condition. This is due to insufficient bounds checking of the display name command line option.
Successful exploitation will enable an attacker to execute arbitrary attacker-supplied instructions and as a consequence gain elevated privileges.
This issue was reported for lbxproxy on the Sun Solaris operating system. It is not known whether this is an issue on other operating systems.
Exploit / POC
Solaris LBXProxy Display Name Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Solaris LBXProxy Display Name Buffer Overflow Vulnerability
Solution:
Patches are available:
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 9
Solution:
Patches are available:
Sun Solaris 7.0_x86
-
Sun 107655-10
http://sunsolve.sun.com
Sun Solaris 7.0
-
Sun 107654-10
http://sunsolve.sun.com
Sun Solaris 8_x86
-
Sun 108653-41
http://sunsolve.sun.com
Sun Solaris 8_sparc
-
Sun 108652-51
http://sunsolve.sun.com
Sun Solaris 9
-
Sun 112785-01
http://sunsolve.sun.com