First published: Mon Dec 31 2001(Updated: )
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =8.0-unkown | |
Sun SunOS | =5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1582 is classified as a high severity vulnerability due to the potential for local users to execute arbitrary code.
To mitigate CVE-2001-1582, it is recommended to apply patches provided by Oracle for Solaris 8 or disable the usage of environment variables in privileged programs.
CVE-2001-1582 affects local users on Sun Solaris 8 and SunOS 5.8 systems that utilize the LDAP naming services library.
CVE-2001-1582 is caused by a buffer overflow vulnerability in the LDAP options environment variable handling in the libsldap library.
CVE-2001-1582 cannot be exploited remotely as it requires local access to the affected system.