OSVDB ID: 8205

Title: Solaris x86 mkcookie Privilege Escalation Overflow

Info

Disclosure

Dec 03, 1998

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A local overflow exists in Solaris. The mkcookie utility fails to sanitize the $HOME environment variable, resulting in a buffer overflow. With a specially crafted request with machine code, a local attacker can cause a buffer overflow and execute arbitrary code with root privilege, resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Disclosure: OSVDB Verified

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Sun Microsystems, Inc.

Solaris

2.5 x86
2.5.1 x86
2.6 x86
7 x86

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/8205