Solaris7 'kcms_configure' vulnerable to an exploitable buffer overflow (NETPATH)
29 Nov. 1999
Summary
'kcms_configure' has a overflow bug with the "-P" option and it has been reported(107339-01). But, this program has another hole. 'kcms_configure' overflows if a long string is specified in NETPATH environment. This security hole is exploitable and with the exploit code provided below root can be obtained.
Credit:
This vulnerability has been discovered by: UNYUN.
------ ex_kcms_configure86.c
/*===============================================================
kcms_configure Exploit for Solaris7 Intel Edition
The Shadow Penguin Security (http://shadowpenguin.backsection.net)
Written by UNYUN (shadowpenguin@backsection.net)
===============================================================*/