7.2
CVSSv2

CVE-2001-1076

Published: 05/07/2001 Updated: 30/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in whodo in Solaris SunOS 5.5.1 up to and including 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.

Vulnerable Product Search on Vulmon Subscribe to Product

sun sunos 5.5

sun sunos 5.5.1

sun sunos 5.8

sun solaris 8.0

sun sunos 5.7

sun solaris 7.0

sun solaris 2.5.1

sun solaris 2.5

sun solaris 2.6

sun sunos -

Exploits

source: wwwsecurityfocuscom/bid/2935/info The 'whodo' utility shipped with Sun Microsystems' Solaris provides a listing of users online and their activities It is installed setuid root because it reads from the 'utmp' log as well as from the process table 'whodo' contains a buffer overflow which can be exploited to gain root privileges ...