vendor:
Kodak Color Management System Configuration Tool
by:
LAST STAGE OF DELIRIUM
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Kodak Color Management System Configuration Tool
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris x86 and Solaris Sparc
1999
Kodak Color Management System Configuration Tool Buffer Overflow
The Kodak Color Management System configuration tool 'kcms_configure' is vulnerable to a buffer overflow that could yield root privileges to an attacker. The bug exists in the KCMS_PROFILES environment variable parser in a shared library 'kcsSUNWIOsolf.so' used by kcms_configure. If an overly long KCMS_PROFILES variable is set and kcms_configure is subsequently run, kcms_configure will overflow. Because the kcms_configure binary is setuid root, the overflow allows an attacker to execute arbitrary code as root. Exploits are available against Solaris x86 and Solaris Sparc.
Mitigation:
Upgrade to the latest version of the Kodak Color Management System configuration tool.