vendor:
Solaris
by:
SecurityFocus
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Solaris
Affected Version From: Solaris 2.6
Affected Version To: Solaris 8
Patch Exists: YES
Related CWE: CVE-2001-0145
CPE: o:sun:solaris
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Intel x86 and Sun Sparc
2001
Solaris ftp Server Buffer Overflow
A problem in the ftp server included with the Solaris Operating System could allow a local user to recover parts of the shadow file, containing encrypted passwords. Due to a previously known problem involving a buffer overflow in glob(), it is possible to cause a buffer overflow in the Solaris ftp server, which will dump parts of the shadow file to core. This can be done with the CWD ~ command, using a non-standard ftp client.
Mitigation:
Upgrade to the latest version of Solaris and apply the latest security patches.