Executive brief
A security vulnerability exists in the 'ps' command, a standard utility used to view running processes on SunOS and Solaris operating systems. Because this utility often runs with elevated system privileges, a local user could exploit this flaw to gain full control over the affected system. This could lead to unauthorized access to sensitive data, system instability, or complete takeover of the server by a non-privileged user.
Technical details
A buffer overflow vulnerability exists in the 'ps' executable within SunOS 5.3 through 5.5.1 (Solaris 2.3 through 2.5.1). The flaw is likely triggered by passing overly long arguments or environment variables to the utility, which is typically installed with setuid root permissions to access process information in kernel memory. A local, unprivileged attacker can exploit this memory corruption to execute arbitrary code with root privileges. Sun Microsystems released security bulletin 149 to address this issue; users should apply the relevant patches for their specific OS version.
Affected products
- Sun Microsystems SunOS 5.3, 5.4, 5.5, 5.5.1
- Sun Microsystems Solaris 2.3, 2.4, 2.5, 2.5.1
Timeline
- 1997-08-01: disclosed: Initial NVD publication date
- 1997-08-01: advisory: Sun Security Bulletin #149 released