vendor:
Solaris
by:
NSFOCUS Security Team
7.2
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: Solaris
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:sun:sun_microsystems:solaris
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris 8 x86
2001
Xlock Heap Overflow Vulnerability
Xlock is a utility for locking X-windows displays. It is installed setuid root because it uses the user's password to authorize access to the display when it is locked. The version of xlock that ships with Solaris as part of OpenWindows contains a heap overflow in it's handling of an environment variable. Local attackers may be able to execute arbitrary code with effective privileges of xlock.
Mitigation:
Upgrade to the latest version of Xlock.