CVE-2000-0337: Buffer Overflow

Published Apr 24, 2000
·
Updated

Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.

Affected Software

4 affected components
Sun SunOS=5.7
Sun SunOS=5.8
Sun Solaris=7.0
Sun Solaris=8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Xsun X server (Solaris 7) from your environment.

    Uninstall or disable the Xsun X server on Solaris 7 systems if X server functionality is not required. Do not run Xsun until a vendor patch or advisory is made available.

  2. Configuration

    Restrict execution of the Xsun binary to trusted administrative accounts by changing filesystem permissions or local access controls so unprivileged local users cannot invoke it until a patch is available.

    Xsun X server (Solaris 7) executable permissions = restrict to administrators/root
  3. Compensating control

    Restrict local interactive access to affected Solaris 7 systems to trusted accounts (disable or limit unprivileged local user shells) and monitor for attempts to execute the Xsun binary until the vulnerability is remediated by the vendor.

Event History

Apr 24, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0337?

CVE-2000-0337 is considered to have a high severity due to its potential to allow local users to gain root privileges.

2

How do I fix CVE-2000-0337?

To mitigate CVE-2000-0337, apply the latest patches provided by Oracle for Solaris 7 and Solaris 8.

3

Who is affected by CVE-2000-0337?

CVE-2000-0337 affects local users of Solaris 7 and Solaris 8 who can exploit a buffer overflow in the Xsun X server.

4

What impact does CVE-2000-0337 have on systems?

CVE-2000-0337 can lead to unauthorized root access, compromising system integrity and security.

5

Is there a workaround for CVE-2000-0337?

A practical workaround for CVE-2000-0337 is to restrict access to the affected Xsun X server and avoid using the -dev parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203