PT-2009-1217 · Sun · Sun Solaris
Published
2009-05-26
·
Updated
2018-10-11
·
CVE-2008-3870
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 8 and 9
Description
The issue is related to an integer overflow in the sadmind service, which can be exploited by remote attackers to execute arbitrary code. This is achieved through a crafted RPC request that triggers a heap-based buffer overflow due to improper memory allocation.
Recommendations
For Sun Solaris version 8, apply the necessary patch to fix the integer overflow issue in the sadmind service.
For Sun Solaris version 9, apply the necessary patch to fix the integer overflow issue in the sadmind service.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sun Solaris