Solaris sadmind Buffer Overflow Vulnerability

BID:866

Info

Solaris sadmind Buffer Overflow Vulnerability

Bugtraq ID: 866
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: Yes
Published: Dec 10 1999 12:00AM
Updated: Dec 10 1999 12:00AM
Credit: This vulnerability was reported to the Incidents list on December 9th, 1999 by several parties who had been attacked and compromised with it. The actual exploit itself was written by Cheez Whiz < [email protected]> June 24, 1999.
Vulnerable: Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 2.6_x86
Sun Solaris 2.6
Sun Solaris 2.5_x86
Sun Solaris 2.5
Not Vulnerable:

Discussion

Solaris sadmind Buffer Overflow Vulnerability

Certain versions of Solaris ship with a version of sadmind which is vulnerable to a remotely exploitable buffer overflow attack. sadmind is the daemon used by Solstice AdminSuite applications to perform distributed system administration operations such as adding users. The sadmind daemon is started automatically by the inetd daemon whenever a request to invoke an operation is received.

Under vulnerable versions of sadmind (2.6 and 7.0 have been tested), if a long buffer is passed to a NETMGT_PROC_SERVICE request (called via clnt_call()), it is possible to overwrite the stack pointer and execute arbitrary code. The actual buffer in questions appears to hold the client's domain name. The overflow in sadmind takes place in the get_auth() function, part of the /usr/snadm/lib/libmagt.so.2 library. Because sadmind runs as root any code launched as a result will run as with root privileges, therefore resulting in a root compromise.

Exploit / POC

Solaris sadmind Buffer Overflow Vulnerability

Below are links to two exploits (sparc and x86) and a program to brute-force the offset value. Optyx <[email protected]> submitted an exploit that includes code to brute-force the offset.

Solution / Fix

Solaris sadmind Buffer Overflow Vulnerability

Solution:
Patches are available to all Sun customers at http://sunsolve.sun.com


Sun Solaris 2.6

Sun Solaris 7.0

Sun Solaris 2.6_x86

Sun Solaris 2.5

Sun Solaris 7.0_x86

Sun Solaris 2.5_x86

Sun Solaris 2.5.1 _x86

Sun Solaris 2.5.1

References

Solaris sadmind Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report