vendor:
CDE Session Manager
by:
LAST STAGE OF DELIRIUM
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CDE Session Manager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris x86
2001
Buffer Overflow in CDE Session Manager ‘dtsession’
The CDE Session Manager 'dtsession' is vulnerable to a buffer overflow that could yield root privileges to an attacker. The bug exists in dtsession's LANG environment variable parser. If an overly long LANG variable is set and dtsession is subsequently run, dtsession will overflow. Because the dtsession binary is setuid root, the overflow allows an attacker to execute arbitrary code as root. An exploit is available against x86 Solaris installations of CDE.
Mitigation:
The user should ensure that the LANG environment variable is not set to an overly long value.