First published: Wed Feb 21 2018(Updated: )
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joyent SmartOS | =20170803 | |
Oracle Solaris | =11 | |
Oracle ZFS Storage Appliance | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1165 is a vulnerability that allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS, Oracle Solaris, and Oracle ZFS Storage Appliance.
CVE-2018-1165 has a severity rating of high (7 out of 10).
To exploit CVE-2018-1165, an attacker must first obtain the ability to execute low-privileged code on the target system.
The affected software includes Joyent SmartOS release-20170803-20170803T064301Z, Oracle Solaris 11, and Oracle ZFS Storage Appliance 8.8.
You can find more information about CVE-2018-1165 on the Joyent and Oracle security advisories.