Search

published date: August 27, 2003

CVE-2003-0609 : Stack-based Buffer Overflow Vulnerability

Description

Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.

Product(s):

  • Sun Solaris 2.6
  • Sun Solaris 2.6 HW3
  • Sun Solaris 2.6 x86HW3
  • Sun Solaris 2.6 HW5
  • Sun Solaris 2.6 x86HW5
  • Sun Solaris 7.0 on x86

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2003-0609, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2003-0609 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?