Vulnerability Name: | CVE-2002-0033 (CCN-8999) | ||||||||||||
Assigned: | 2002-05-06 | ||||||||||||
Published: | 2002-05-06 | ||||||||||||
Updated: | 2018-10-30 | ||||||||||||
Summary: | Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name. | ||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: BUGTRAQ Type: Vendor Advisory 20020505 [LSD] Solaris cachefsd remote buffer overflow vulnerability Source: CCN Type: BugTraq Mailing List, Sun May 05 2002 - 22:32:23 CDT [LSD] Solaris cachefsd remote buffer overflow vulnerability Source: MITRE Type: CNA CVE-2002-0033 Source: CONFIRM Type: Patch, Vendor Advisory http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309 Source: CCN Type: Sun Alert ID: 44309 Buffer Overflow in cachefsd in Solaris Source: CCN Type: CERT Advisory CA-2002-11 Heap Overflow in Cachefs Daemon (cachefsd) Source: CERT Type: Patch, Third Party Advisory, US Government Resource CA-2002-11 Source: CCN Type: CIAC Information Bulletin M-078 Sun Heap Overflow in Cachefs Daemon (cachefsd) Source: CCN Type: Cisco Systems Inc. Security Advisory, 2002 July 24 16:00 (UTC +0000) Heap Overflow in Solaris cachefs Daemon Source: XF Type: UNKNOWN solaris-cachefsd-name-bo(8999) Source: CCN Type: US-CERT VU#635811 Sun Solaris cachefsd vulnerable to heap overflow in cfsd_calloc() function via long string of characters Source: CERT-VN Type: US Government Resource VU#635811 Source: CCN Type: OSVDB ID: 779 Solaris RPC cachefsd cfsd_calloc Function Remote Overflow Source: BID Type: UNKNOWN 4674 Source: CCN Type: BID-4674 Solaris cachefsd Heap Overflow Vulnerability Source: XF Type: UNKNOWN solaris-cachefsd-name-bo(8999) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:124 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:31 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |