First published: Thu Jun 19 2003(Updated: )
Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =7.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =2.6 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8.0 | |
Sun SunOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1067 has a critical severity rating due to the potential for local users to gain root privileges.
To fix CVE-2003-1067, updates or patches provided by the vendor for affected Solaris versions should be applied.
CVE-2003-1067 affects Solaris versions 2.6 through 9, including specific versions like 5.7, 5.8, and 8.0.
Exploiting CVE-2003-1067 allows local users to execute arbitrary code with root privileges, compromising system security.
CVE-2003-1067 is primarily a local privilege escalation vulnerability, meaning it requires local access to the system to exploit.