vendor:
AIX and Solaris
by:
UNYUN
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: AIX and Solaris
Affected Version From: IBM's AIX and Sun Microsystem's Solaris
Affected Version To: IBM's AIX and Sun Microsystem's Solaris
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Sparc
1998
Buffer Overflow in libc’s Handling of the LC_MESSAGES Environment Variable
A buffer overflow in libc's handling of the LC_MESSAGES environment variable allows a malicious user to exploit any suid root program linked agains libc to obtain root privileges. This problem is found in both IBM's AIX and Sun Microsystem's Solaris. This vulnerability allows local users to gain root privileges.
Mitigation:
Ensure that the LC_MESSAGES environment variable is set to a valid value.