PT-2003-2023 · Sun · Sun Solaris
Published
2003-12-31
·
Updated
2018-10-30
·
CVE-2003-1066
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 2.6 through 9
Description
The issue is related to a buffer overflow in the syslog daemon, which can be triggered by remote attackers sending long syslog UDP packets. This can cause a denial of service, leading to the syslogd crash, and potentially allow the execution of arbitrary code.
Recommendations
For Sun Solaris versions 2.6 through 9, consider disabling the vulnerable syslog daemon until a patch is available. Restrict access to the syslog service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Solaris