Executive brief
A security vulnerability exists in a system configuration tool within the Solaris operating system. A local user could exploit this flaw to gain unauthorized administrative control over the system. This could lead to a total loss of data confidentiality and system integrity.
Technical details
A buffer overflow vulnerability exists in the ffbconfig utility, a tool used to configure Creator Graphics Accelerator features in Sun Solaris 2.5.1. The flaw is triggered when the utility handles overly long input arguments. Because ffbconfig is typically installed with setuid root permissions, a local attacker can exploit this overflow to execute arbitrary code with root privileges. This is a classic stack-based buffer overflow resulting from a lack of bounds checking on command-line arguments.
Affected products
- Sun Microsystems Solaris 2.5.1
Timeline
- 1997-02-10: disclosed