Executive brief
A critical vulnerability exists in the core networking libraries of AIX and Solaris operating systems. These systems use a specific function to translate computer names into IP addresses; by providing a specially crafted, malicious name via DNS, an attacker can take complete control of the server. This allows for unauthorized access to sensitive data, system-wide outages, or the installation of malicious software with the highest possible privileges (root).
Technical details
A classic buffer overflow vulnerability exists within the 'gethostbyname' library function used by AIX and Solaris for DNS resolution. The flaw is triggered when the function processes a DNS response containing an oversized or corrupt host name that exceeds the allocated buffer size. Because this library is utilized by numerous privileged system services and applications, a remote, unauthenticated attacker can exploit this overflow to overwrite memory and execute arbitrary code. Successful exploitation typically results in a full compromise of the affected system with root-level privileges. The attack vector is the network, specifically targeting any service that performs name resolution on untrusted input.
Affected products
- IBM AIX
- Sun Microsystems Solaris
Timeline
- 1996-12-10: disclosed