vendor:
Color Management System
by:
LAST STAGE OF DELIRIUM
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Color Management System
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-1999-0907
CPE: a:kodak:color_management_system
Platforms Tested: Solaris x86, Solaris Sparc
1999
Kodak Color Management System ‘kcms_configure’ Buffer Overflow Vulnerability
The Kodak Color Management System configuration tool 'kcms_configure' is vulnerable to a buffer overflow that could yield root privileges to an attacker. The bug exists in the KCMS_PROFILES environment variable parser in a shared library 'kcsSUNWIOsolf.so' used by kcms_configure. If an overly long KCMS_PROFILES variable is set and kcms_configure is subsequently run, kcms_configure will overflow. Because the kcms_configure binary is setuid root, the overflow allows an attacker to execute arbitrary code as root.
Mitigation:
Upgrade to a non-vulnerable version or apply the appropriate patch.