vendor:
Solaris
by:
Nathaniel Singer, Joe Rozner
10
CVSS
CRITICAL
Stack-based Buffer Overflow
121
CWE
Product Name: Solaris
Affected Version From: Oracle Solaris 9 (some releases), 10 (all releases), 11.0
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2020-14871
CPE: o:oracle:solaris:11.0
Platforms Tested:
2020
Solaris SunSSH 11.0 x86 – libpam Remote Root (3)
CVE-2020-14871 is a critical pre-authentication (via SSH) stack-based buffer overflow vulnerability in the Pluggable Authentication Module (PAM) in Oracle Solaris. PAM is a dynamic authentication component that was integrated into Solaris back in 1997 as part of Solaris 2.6. The vulnerability received a CVSSv3 score of 10.0, the maximum possible score.
Mitigation:
Apply the latest patches provided by Oracle to fix the vulnerability.