All the latest UK technology news, reviews and analysis

Sun logs in buffer vulnerability

by James Middleton

13 Dec 2001

Be the first to comment

  • Tweet this

Security authorities have issued a warning about a "serious vulnerability" in the login system used by Sun Solaris.

Versions of Solaris 8 and earlier are vulnerable to an exploit that could allow remote attackers to execute arbitrary commands on a system with super-user privileges.

Although systems are only vulnerable if interactive connections are allowed, such as Telnet or Rlogin which are enabled by default, security firm ISS X-Force warned that an exploit is already in circulation on the underground.

According to research, a static buffer overflow vulnerability is present in the login system which incorrectly handles long environment variables passed to it by the connection program, such as Telnet.

At present, Sun has not released a fix. The advisory has gone out early because the exploit is already in the public arena.

ISS X-Force suggests disabling terminal connection services and installing Secure Shell as a workaround until the patch comes out.

A Computer Emergency Response Team advisory is available here, and the Sun patches will be downloadable from here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

c# or asp.net Software Developer

Job Specification For: Software Developer...

Project Manager for UI Development

A global Investment Bank requires a Project Manager to...

Web Developer, .Net Software Developer - ASP.Net, C#, HTML, CSS

Web Developer, .Net Software Developer - ASP.Net, C...

Verint Voice Recording Support Engineer

Verint Voice Recording Support Engineer (Verint / Nice...

To send to more than one email address, simply separate each address with a comma.