CVE-2001-1076: Buffer Overflow
Published Jul 5, 2001
·Updated
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
Affected Software
10 affected components
Sun Solaris=2.5.1
Sun Solaris=2.5
Sun SunOS=5.7
Sun SunOS=5.5
Sun SunOS=5.8
Sun Solaris=7.0
Sun SunOS=5.5.1
Sun Solaris=2.6
Sun Solaris=8.0
Sun SunOS
Remediation
Patch Available
Event History
Jul 5, 2001
CVE Published
04:00 AM
Feb 2, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1076?
CVE-2001-1076 has a moderate severity level due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2001-1076?
To fix CVE-2001-1076, apply the latest patches or updates available for Solaris versions vulnerable to this buffer overflow.
3
Which versions of Solaris are affected by CVE-2001-1076?
CVE-2001-1076 affects Solaris SunOS versions 5.5, 5.5.1, 5.7, 5.8, and specific versions of Solaris 2.5.x.
4
Can CVE-2001-1076 be exploited remotely?
CVE-2001-1076 is a local vulnerability and requires an authenticated user to exploit it.
5
What component is vulnerable in CVE-2001-1076?
The vulnerability in CVE-2001-1076 resides in the 'whodo' command.