Vulnerability Name:

CVE-2008-4556 (CCN-45858)

Assigned:2008-10-14
Published:2008-10-14
Updated:2018-10-11
Summary:Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2008-4556

Source: OSVDB
Type: UNKNOWN
50019

Source: CCN
Type: RISE-2008001
Sun Solstice AdminSuite sadmind adm_build_path() Buffer Overflow Vulnerability

Source: MISC
Type: Exploit
http://risesecurity.org/advisories/RISE-2008001.txt

Source: CCN
Type: SA32283
Sun Solaris "sadmind" Buffer Overflow Vulnerability

Source: SECUNIA
Type: Vendor Advisory
32283

Source: CCN
Type: SA32812
Avaya CMS Solaris "sadmind" Buffer Overflow Vulnerability

Source: SECUNIA
Type: UNKNOWN
32812

Source: SREASON
Type: UNKNOWN
4408

Source: CCN
Type: SECTRACK ID: 1021059
Solstice AdminSuite sadmind Buffer Overflow in adm_build_path() Lets Remote Users Execute Arbitrary Code

Source: SUNALERT
Type: UNKNOWN
245806

Source: CCN
Type: Sun Alert ID: 245806
A Buffer Overflow Security Vulnerability in the Solaris sadmind(1M) Daemon May Lead to Execution of Arbitrary Code

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2008-448.htm

Source: CCN
Type: NORTEL BULLETIN ID: 2009009568, Rev 1
Nortel Response to Sun Alerts 245806 & 259468 - Solaris 8 & 9 - Vulnerabilities associated with sadmind(1M) Daemon

Source: CCN
Type: OSVDB ID: 49111
Sun Solstice AdminSuite on Solaris sadmind adm_build_path Function Remote Overflow

Source: BUGTRAQ
Type: UNKNOWN
20081014 [RISE-2008001] Sun Solstice AdminSuite sadmind adm_build_path()Buffer Overflow Vulnerability

Source: BID
Type: Exploit
31751

Source: CCN
Type: BID-31751
Sun Solstice AdminSuite 'sadmind' 'adm_build_path()' Remote Stack Buffer Overflow Vulnerability

Source: SECTRACK
Type: UNKNOWN
1021059

Source: CCN
Type: Sun Web site
Sun Microsystems

Source: VUPEN
Type: UNKNOWN
ADV-2008-2824

Source: VUPEN
Type: UNKNOWN
ADV-2008-3230

Source: XF
Type: UNKNOWN
sunsolstice-adminsuite-admbuildpath-bo(45858)

Source: XF
Type: UNKNOWN
sunsolstice-adminsuite-admbuildpath-bo(45858)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:5543

Source: EXPLOIT-DB
Type: UNKNOWN
6786

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sun:solaris:8:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9:*:x86:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:5543
    V
    A Buffer Overflow Security Vulnerability in the Solaris sadmind(1M) Daemon May Lead to Execution of Arbitrary Code
    2010-09-20
    BACK
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 9
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 9