Solaris UUCP Local Buffer Overflow Vulnerability
BID:6600
Info
Solaris UUCP Local Buffer Overflow Vulnerability
| Bugtraq ID: | 6600 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 13 2003 12:00AM |
| Updated: | Jan 13 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to hipnosis hipnosis <[email protected]>. The issue was also discovered independently by Gloomy. |
| Vulnerable: |
Sun Solaris 8_sparc |
| Not Vulnerable: | |
Discussion
Solaris UUCP Local Buffer Overflow Vulnerability
A vulnerability has been discovered in the UUCP utility for Solaris. It is possible to trigger a buffer overflow in UUCP by sending excessive data as a user-supplied command line parameter. Although it has not yet been confirmed, it is likely that this issue is exploitable to execute arbitrary code. As UUCP is typically installed setuid root, all commands will be executed with superuser privileges.
A vulnerability has been discovered in the UUCP utility for Solaris. It is possible to trigger a buffer overflow in UUCP by sending excessive data as a user-supplied command line parameter. Although it has not yet been confirmed, it is likely that this issue is exploitable to execute arbitrary code. As UUCP is typically installed setuid root, all commands will be executed with superuser privileges.
Exploit / POC
Solaris UUCP Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Solaris UUCP Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Solaris UUCP Local Buffer Overflow Vulnerability
References:
References:
- Solaris uucp Buffer Overflow Vulnerability (iDEFENSE)
- Buffer Overflow in uucp of SunOS 5.8 (hipnosis hipnosis
)