vendor:
Solaris Operating Environment
by:
Pablo Sor
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Solaris Operating Environment
Affected Version From: Solaris 7
Affected Version To: Solaris 8
Patch Exists: YES
Related CWE: N/A
CPE: o:sun:solaris
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: x86
2001
tip Buffer Overflow Vulnerability
A problem with tip could lead to a buffer overflow. Due to the improper handling of environment variables by tip, it is possible to overflow a buffer in the program, and execute arbitrary code. The tip binary is suid uucp, and exploitation could lead to an euid of uucp. Therefore, it is possible for a local user to execute arbitrary code, and gain an euid of uucp, with the potential of gaining privileges elevated to root.
Mitigation:
Upgrade to the latest version of tip.