7.2
CVSSv2

CVE-2001-0426

Published: 02/07/2001 Updated: 30/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.

Vulnerable Product Search on Vulmon Subscribe to Product

sun solaris 2.6

sun solaris 8.0

sun sunos -

sun sunos 5.7

sun solaris 7.0

sun sunos 5.8

Exploits

/* source: wwwsecurityfocuscom/bid/2603/info The CDE Session Manager 'dtsession' is vulnerable to a buffer overflow that could yield root privileges to an attacker The bug exists in dtsession's LANG environment variable parser If an overly long LANG variable is set and dtsession is subsequently run, dtsession will overflow Because the ...