Solaris chkperm Buffer Overflow Vulnerability
BID:918
Info
Solaris chkperm Buffer Overflow Vulnerability
| Bugtraq ID: | 918 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-0055 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 06 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list on January 6, 2000, by Kim Yong Jun <[email protected]> |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 _ppc Sun Solaris 2.5.1 Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86HW5/98 Sun Solaris 2.6_x86HW3/98 Sun Solaris 2.6_x86 Sun Solaris 2.6 HW5/98 Sun Solaris 2.6 HW3/98 Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 Sun Solaris 2.3 |
| Not Vulnerable: | |
Discussion
Solaris chkperm Buffer Overflow Vulnerability
A buffer overrun exists in the 'chkperm' program, as included by Sun in its version of AT&T's FACE (Framed Access Command Environment). By supplying a well crafted buffer of executable code to the -n option to the chkperm executable, it may be possible to execute arbitrary commands as root.
It has been publicly reported that this vulnerability is unexploitable by conventional means, under both Sparc and X86 versions of Solaris. This does not mean, necessarily, that the possibility of an exploit existing now, or in the future, is 0. The safest course of action is still to repair the problem, either by acquiring a patch from the vendor, or by removing the setuid and setgid bits from the chkperm binary.
A buffer overrun exists in the 'chkperm' program, as included by Sun in its version of AT&T's FACE (Framed Access Command Environment). By supplying a well crafted buffer of executable code to the -n option to the chkperm executable, it may be possible to execute arbitrary commands as root.
It has been publicly reported that this vulnerability is unexploitable by conventional means, under both Sparc and X86 versions of Solaris. This does not mean, necessarily, that the possibility of an exploit existing now, or in the future, is 0. The safest course of action is still to repair the problem, either by acquiring a patch from the vendor, or by removing the setuid and setgid bits from the chkperm binary.
Exploit / POC
Solaris chkperm Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Solaris chkperm Buffer Overflow Vulnerability
Solution:
Sun has made patches available for this problem. Patches are available to all Sun customers at http://sunsolve.sun.com
Sun Solaris 7.0
Sun Solaris 7.0_x86
Sun Solaris 2.5_x86
Sun Solaris 2.6
Sun Solaris 2.6_x86
Sun Solaris 2.5
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _x86
Solution:
Sun has made patches available for this problem. Patches are available to all Sun customers at http://sunsolve.sun.com
Sun Solaris 7.0
Sun Solaris 7.0_x86
Sun Solaris 2.5_x86
Sun Solaris 2.6
Sun Solaris 2.6_x86
Sun Solaris 2.5
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _x86
References
Solaris chkperm Buffer Overflow Vulnerability
References:
References:
- Sun Patch Access Page (Sun Microsystems)
- Sun Patches List (Sun Microsystems)
- Sunsolve Online(tm) (Sun Microsystems)