Solaris Whodo Buffer Overflow Vulnerability (Exploit, SOR, CFTIME)
8 Jul. 2001
Summary
Whodo shows the processes in use at each console and terminal. A security vulnerability in the product allows local users to cause a stack overflow in the product causing it to execute arbitrary code. Since the program runs at higher privileges than the common user, an unprivileged user can gain root privileges.
Credit:
The information has been provided by Pablo Sor.
Vulnerable systems:
SunOS version 5.5.1
SunOS version 5.7
SunOS version 5.8
Immune systems:
SunOS version 5.6
The whodo program is installed setuid root by default in Solaris. The program contains vulnerability in its handling of data that arrives from the environmental variables, if one of these variables exceeds predefined length, an exploitable stack overflow can occur. Through exploiting of this vulnerability, an attacker can gain effective UID root.
Vendor status:
Sun Microsystems was notified on June 28, 2001. Patches are to be released shortly.