PT-1996-1014 · Oracle+1 · Solaris+1
Published
1996-12-10
·
Updated
2008-09-09
·
CVE-1999-0101
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AIX (affected versions not specified)
Solaris (affected versions not specified)
Description
The issue is related to a buffer overflow in the "gethostbyname" library call, which can be exploited through corrupt DNS host names to gain root access.
Recommendations
For AIX, update to a version that includes a fix for the buffer overflow in the "gethostbyname" library call.
For Solaris, update to a version that includes a fix for the buffer overflow in the "gethostbyname" library call.
As a temporary workaround, consider restricting DNS host name parsing to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aix
Solaris