vendor:
Solaris
by:
51
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Solaris
Affected Version From: Solaris 8
Affected Version To: Solaris 8
Patch Exists: NO
Related CWE:
CPE: o:sun:solaris:8
Platforms Tested: x86 Sun, Sparc Sun
2001
Buffer Overflow in Solaris mailtool Program
The mailtool program included with OpenWindows in Solaris contains a buffer overflow vulnerability. This vulnerability may allow local users to execute arbitrary code or commands with the group 'mail' privileges. The overflow occurs when a string exceeding approximately 1010 characters is given as the OPENWINHOME environment variable.
Mitigation:
Apply the necessary patches provided by the vendor.