vendor:
Solaris 7
by:
SecurityFocus
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Solaris 7
Affected Version From: Solaris 7
Affected Version To: Solaris 7
Patch Exists: YES
Related CWE: CVE-2001-0206
CPE: o:sun:solaris:7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris
2001
Solaris 7 lpset -r Buffer Overflow Vulnerability
A vulnerability exists in the handling of the -r option to the lpset program, as included in Solaris 7 from Sun Microsystems. The -r option is undocumented. As such, its use in unknown. However, when supplied a well crafted buffer containing executable code, it is possible to execute arbitrary commands as root.
Mitigation:
Upgrade to the latest version of Solaris 7 or apply the patch from Sun Microsystems.