vendor:
Solaris 10
by:
Charles Stevenson
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Solaris 10
Affected Version From: Solaris 10
Affected Version To: Solaris 10
Patch Exists: YES
Related CWE: N/A
CPE: o:sun:solaris:10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: x86
2005
Solaris 10 DtPrintinfo/Session Exploit (x86)
This exploit is a buffer overflow vulnerability in Solaris 10 DtPrintinfo/Session. It was discovered by Charles Stevenson (core) in 2005 and is used to gain root access. The exploit uses an environment variable to overwrite the return address of the stack and execute malicious code.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of Solaris 10.