Platform Load Sharing Facility EAuth Component Buffer Overflow Vulnerability
BID:9719
Info
Platform Load Sharing Facility EAuth Component Buffer Overflow Vulnerability
| Bugtraq ID: | 9719 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0317 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Discovery of this vulnerability has been credited to Tomasz Grabowski <[email protected]>. |
| Vulnerable: |
Platform LSF 6.0 Platform LSF 5.1 Platform LSF 5.0 Platform LSF 4.2 Platform LSF 4.0 |
| Not Vulnerable: | |
Discussion
Platform Load Sharing Facility EAuth Component Buffer Overflow Vulnerability
Load Sharing Facility eauth component has been reported prone to a buffer overflow vulnerability. The issue presents itself due to a lack of bounds checks performed on data that is passed to eauth. By supplying excessive data, an attacker may corrupt data adjacent to the affected buffer and thereby overwrite a saved instruction pointer. An attacker may leverage this issue to influence program execution flow into attacker-supplied instructions.
Load Sharing Facility eauth component has been reported prone to a buffer overflow vulnerability. The issue presents itself due to a lack of bounds checks performed on data that is passed to eauth. By supplying excessive data, an attacker may corrupt data adjacent to the affected buffer and thereby overwrite a saved instruction pointer. An attacker may leverage this issue to influence program execution flow into attacker-supplied instructions.
Exploit / POC
Platform Load Sharing Facility EAuth Component Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Platform Load Sharing Facility EAuth Component Buffer Overflow Vulnerability
Solution:
The vendor has provided a fix to address this issue. Although unconfirmed, it has been reported that customers may download an appropriate patch as follows:
FTP Server: ftp.platform.com
Path: patches/<version>/os/<os>/eauth*
Example: patches/5.1/os/sparc-sol7-64/eauth5.1_sparc-sol7-64.Z
Solution:
The vendor has provided a fix to address this issue. Although unconfirmed, it has been reported that customers may download an appropriate patch as follows:
FTP Server: ftp.platform.com
Path: patches/<version>/os/<os>/eauth*
Example: patches/5.1/os/sparc-sol7-64/eauth5.1_sparc-sol7-64.Z
References
Platform Load Sharing Facility EAuth Component Buffer Overflow Vulnerability
References:
References:
- Platform Homepage (Platform)
- Lam3rZ Security Advisory #1/2004: LSF eauth vulnerability leads toremote code ex (Tomasz Grabowski
)