vendor:
by:
_PHANTOM_
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
1996
SUDO.BIN Exploit
This exploit takes advantage of a buffer overflow vulnerability in the SUDO.BIN program. It overflows the buffer with a shellcode that executes a shell command. It then sets the NLSPATH environment variable to the overflowed buffer and executes the SUDO.BIN program with the 'bash' command.
Mitigation:
The vulnerability can be mitigated by applying a patch or updating the SUDO.BIN program to a version that is not vulnerable to buffer overflow attacks.