Required CVE Record Information
Description
Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in the format parameter of the doprf function. NOTE: this issue normally does not cross privilege boundaries, except in cases of external introduction of malicious message files, or if it is leveraged with other vulnerabilities such as CVE-2006-6494.
References 10 Total
- secunia.com: 23317 third-party-advisory
- secunia.com: 23991 third-party-advisory
- labs.idefense.com: 20061212 Sun Microsystems Solaris ld.so 'doprf()' Buffer Overflow Vulnerability third-party-advisory
- sunsolve.sun.com: 102724 vendor-advisory
- securityfocus.com: 21564 vdb-entry
- securitytracker.com: 1017376 vdb-entry
- vupen.com: ADV-2006-4979 vdb-entry
- oval.cisecurity.org: oval:org.mitre.oval:def:1909 vdb-entrysignature
- exchange.xforce.ibmcloud.com: solaris-ld-doprf-bo(30848) vdb-entry
- http://support.avaya.com/elmodocs2/security/ASA-2007-019.htm
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 10 Total
- secunia.com: 23317 third-party-advisoryx_transferred
- secunia.com: 23991 third-party-advisoryx_transferred
- labs.idefense.com: 20061212 Sun Microsystems Solaris ld.so 'doprf()' Buffer Overflow Vulnerability third-party-advisoryx_transferred
- sunsolve.sun.com: 102724 vendor-advisoryx_transferred
- securityfocus.com: 21564 vdb-entryx_transferred
- securitytracker.com: 1017376 vdb-entryx_transferred
- vupen.com: ADV-2006-4979 vdb-entryx_transferred
- oval.cisecurity.org: oval:org.mitre.oval:def:1909 vdb-entrysignaturex_transferred
- exchange.xforce.ibmcloud.com: solaris-ld-doprf-bo(30848) vdb-entryx_transferred
- http://support.avaya.com/elmodocs2/security/ASA-2007-019.htm x_transferred