Oracle Sun Solaris Kernel USB Configuration Descriptor Local Buffer Overflow Vulnerability
BID:48790
Info
Oracle Sun Solaris Kernel USB Configuration Descriptor Local Buffer Overflow Vulnerability
| Bugtraq ID: | 48790 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2295 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 19 2011 12:00AM |
| Updated: | Nov 02 2011 08:23PM |
| Credit: | Andy Davis of NGS Secure. |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.B0.73 Xerox FreeFlow Print Server (FFPS) 73.A3.31 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 11 Express Sun Solaris 10_x86 Sun Solaris 10_sparc Avaya Interactive Response 4.0 Avaya Interactive Response 3.0 Avaya CMS Server 16.2 Avaya CMS Server 16.1 Avaya CMS Server 16.0 Avaya CMS Server 15.0 |
| Not Vulnerable: | |
Discussion
Oracle Sun Solaris Kernel USB Configuration Descriptor Local Buffer Overflow Vulnerability
The Oracle Sun Solaris kernel is prone to a local stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code with superuser privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the kernel, denying service to legitimate users.
This vulnerability affects the following supported versions:
8, 9, 10, 11 Express
The Oracle Sun Solaris kernel is prone to a local stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code with superuser privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the kernel, denying service to legitimate users.
This vulnerability affects the following supported versions:
8, 9, 10, 11 Express
Exploit / POC
Oracle Sun Solaris Kernel USB Configuration Descriptor Local Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Sun Solaris Kernel USB Configuration Descriptor Local Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Sun Solaris Kernel USB Configuration Descriptor Local Buffer Overflow Vulnerability
References:
References:
- NGS00042 Patch Notification: Solaris USB configuration descriptor kernel stack (NGS Secure)
- NGS00042 Technical Advisory: Solaris 11 USB hub class descriptor kernel stack o (NGSSecure)
- ASA-2011-221 Oracle Critical Update CVE-2011-2295 (Avaya)
- Oracle Critical Patch Update Advisory - July 2011 (Oracle)
- Xerox Security Bulletin XRX11-003 (Xerox)