PT-2020-4751 · Oracle · Oracle Solaris
Aaron Carreras
+2
·
Published
2020-10-20
·
Updated
2025-02-07
·
CVE-2020-14871
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Oracle Solaris versions 10 and 11
Description:
The issue is related to a buffer overflow vulnerability in the Pluggable authentication module of Oracle Solaris, which can be exploited by an unauthenticated attacker with network access via multiple protocols to compromise the system. This vulnerability may significantly impact additional products and can result in the takeover of Oracle Solaris. There have been reports of real-world attacks exploiting this issue, with an exploit being sold on the black market. The vulnerability is easily exploitable and can allow remote takeover of the system.
Recommendations:
For Oracle Solaris versions 10 and 11, update to a version that is not affected by this vulnerability, as the exact fixed version is not specified. As a temporary workaround, consider disabling the
parse user name() function of the Pluggable authentication module until a patch is available. Restrict access to the Pluggable authentication module to minimize the risk of exploitation. Avoid using the Pluggable authentication module for SSHD or other network services until the issue is resolved.Exploit
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Solaris