vendor:
Solaris
by:
UNYUN
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Solaris
Affected Version From: Solaris 8
Affected Version To: Solaris 7
Patch Exists: YES
Related CWE: N/A
CPE: o:sun:solaris
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris 8, Solaris 7
2002
Solaris ximp40 shared library exploit for Solaris8 Intel Edition
A problem in the ximp40 library packaged with Openwin could allow a user to gain elevated privileges. Due to a problem with the handling of input by the programs linked against ximp40.so.2, it is possible to supply a long string, approximately 272 bytes, to the arg0 of the command, which will overwrite stack variables, including the return address of the program.
Mitigation:
Upgrade to the latest version of Solaris and Openwin.