|
|
| |
| A vulnerability has been discovered in Sun Solaris, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an integer overflow error in "sadmind" when allocating memory for incoming "sadmind" requests. This can be exploited to cause a heap-based buffer overflow via a specially crafted RPC request. Successful exploitation may allow execution of arbitrary code. |
| |
Credit:
The information has been provided by Alin Rad Pop.
The original article can be found at: http://risesecurity.org/advisories/RISE-2008001.txt
|
| |
Vulnerable Systems:
* Solaris 8
* Solaris 9
Immune Systems:
* Solaris 10
Patch Availability:
http://sunsolve.sun.com/search/document.do?assetkey=1-21-116442-02-1
CVE Information:
CVE-2008-3870
Disclosure Timeline:
31/10/2008 - Vendor notified.
01/11/2008 - Vendor response.
23/05/2009 - Public disclosure.
|
|
|