CVE-2001-0652: High severity Sun SunOS vulnerability
Published Oct 30, 2001
·Updated
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.
Affected Software
1 affected component
Sun SunOS<=5.9
Event History
Oct 30, 2001
CVE Published
05:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0652?
CVE-2001-0652 has a high severity rating due to the potential for local users to gain root privileges.
2
How do I fix CVE-2001-0652?
To fix CVE-2001-0652, modify the XFILESEARCHPATH and XUSERFILESEARCHPATH environmental variables to use shorter values.
3
Which versions are affected by CVE-2001-0652?
CVE-2001-0652 affects Solaris versions 2.6 through 8.
4
Who is impacted by CVE-2001-0652?
Local users of affected Solaris systems are at risk from CVE-2001-0652.
5
What causes CVE-2001-0652?
CVE-2001-0652 is caused by a heap overflow vulnerability in the xlock utility.