vendor:
Solaris7 Intel Edition
by:
UNYUN
7.2
CVSS
HIGH
Buffer Overflow
120 (Buffer Copy without Checking Size of Input)
CWE
Product Name: Solaris7 Intel Edition
Affected Version From: Solaris7 Intel Edition
Affected Version To: Solaris7 Intel Edition
Patch Exists: YES
Related CWE: N/A
CPE: o:sun:sunos:7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris7 Intel Edition
2001
kcms_configure Exploit for Solaris7 Intel Edition
The binary kcms_configure, part of the Kodak Color Management System package shipped with OpenWindows (and ultimately, Solaris) is vulnerable to a local buffer overflow. The buffer which the contents of the environment variable NETPATH are copied into has a predetermined length, which if exceeded can corrupt the stack and cause aribtrary code hidden inside of the oversized buffer to be executed. kcms_configure is installed setuid root and exploitation will result in a local root compromise.
Mitigation:
Ensure that the environment variable NETPATH is not set to a value that exceeds the predetermined length.