Heap Overflow in Solaris cachefs Daemon

Related Vulnerabilities: CVE-2002-0033   CVE-2002-0084   CVE-2002-0085   CVE-2003-1063  

This advisory describes a vulnerability that affects Cisco products and applications that are installed on the Solaris operating system, and is based on the vulnerability of an common service within the Solaris operating system, not due to a defect of the Cisco product or application. A vulnerability in the "cachefs" program was discovered that enables an attacker to execute arbitrary code under Solaris OS. This vulnerability was publicly announced in the CERT Advisory CA-2002-11. All Cisco products and applications that are installed on Solaris OS are considered vulnerable to the underlying operating system vulnerability, unless the workaround was applied. This vulnerability is described in details in Sun(sm) Alert Notification at http://sunsolve.sun.com/search/document.do?assetkey=1-26-44309-1 . No other Cisco product is vulnerable. Sun is working on a patch. Until the patch is released all affected customers are advised to apply the workaround described in the workaround section. This advisory is available at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020724-solaris-cachefs.