Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Solaris ld.so.1 buffer overflow

Re: Solaris ld.so.1 buffer overflow

From: Crist J. Clark <cristjc_at_comcast.net>
Date: Fri, 1 Aug 2003 13:58:48 -0700

On Tue, Jul 29, 2003 at 11:36:18PM +0300, Jouko Pynnonen wrote:
>
> OVERVIEW
> ========
>
> There is a buffer overflow vulnerability in the Solaris runtime linker,
> /lib/ld.so.1. A local user can gain elevated privileges if there are
> any dynamically linked, executable SUID/SGID programs in the
> filesystem.
[snip]

According to the Sun Alert on this vulnerability,

  http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55680

Various patchlevels of Solaris 2.6, 7, 8, and 9 sparc and i386 are all
vulnerable.

On Solaris 2.5.1,

  $ uname -a
  SunOS wallace 5.5.1 Generic_103640-40 sun4u sparc SUNW,Ultra-Enterprise

When I try the simple,

  $ LD_PRELOAD=/`perl -e 'print "A"x2000'`/ passwd
  passwd: Changing password for cclark
  Enter login(NIS) password:

It doesn't crash. That reassures me somewhat, but does anyone know if
2.5.1 is not listed because it is (a) no longer supported and not
tested and patched, or (b) not actually vulnerable?

Thanks.

-- 
Crist J. Clark                     |     cjclark_at_alum.mit.edu
                                   |     cjclark_at_jhu.edu
http://people.freebsd.org/~cjc/    |     cjc@freebsd.org
Received on Aug 04 2003
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos