CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
19.7%
A buffer overflow in the mailx program on Solaris systems can allow an intruder to execute code with the privileges of the mail group.
A buffer overflow in the -F option of the mailx program on Solaris systems may allow an intruder to execute code with the privileges of the group of the owner of the file (i.e. mailx is setgid mail). An exploit is publicly available that reportedly works against Solaris on Intel systems.
A local intruder can execute code with the privileges of the mail group.
We are currently unaware of any patches to fix the buffer overflow.
Until a patch can be developed, remove the setgid bit from the mailx program.
Javascript is disabled. Click here to view vendors.
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
This vulnerability was discovered by Pablo Sor, Buenos Aires, Argentina,and documented with the aid of the Security Focus Vulnerability Help Team.
This document was written by Shawn V. Hernan
CVE IDs: | CVE-2001-0565 |
---|---|
Severity Metric: | 14.55 Date Public: |