J-Security Center

Title: Sun Solaris UTMP_Update Local Buffer Overflow Vulnerability

Severity: HIGH

Description:

Solaris is the freely available, open source UNIX Operating System distributed by Sun Microsystems.

A problem in Solaris could make it possible for a local user to gain elevated privileges.

It has been reported that a problem in the Solaris utmp_update binary exists. Due to insufficient bounds checking, it may be possible to trigger a buffer overflow in this program. This will result in sensitive regions of memory being corrupted with attacker-supplied values. This could lead to a local attacker gaining elevated privileges through execution of arbitrary attacker-supplied instructions.

Few details are available about the issue. However, it should be noted that the program is installed with, and executes with privileges. Therefore, exploitation of this program would lead to a local attacker gaining elevated privileges.

Affected Products:

  • Sun Solaris 2.6
  • Sun Solaris 2.6_x86
  • Sun Solaris 7.0
  • Sun Solaris 7.0_x86
  • Sun Solaris 8
  • Sun Solaris 8_x86
  • Sun Solaris 9

References:

  • Sun Microsystems: 50008

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.