CVE-1999-0315

Solaris - Buffer Overflow in fdformat Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0315. PoCs published by Cristian Schipor.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Solaris 2.4 and 2.5.1 via the fdformat binary. It uses SPARC shellcode to execute arbitrary commands, leveraging stack manipulation to achieve remote code execution.

Description

Buffer overflow in Solaris fdformat command gives root access to local users.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cristian Schipor · clocalsolaris
https://www.exploit-db.com/exploits/328

This exploit targets a buffer overflow vulnerability in Solaris 2.4 and 2.5.1 via the fdformat binary. It uses SPARC shellcode to execute arbitrary commands, leveraging stack manipulation to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Solaris 2.4 and 2.5.1 (fdformat binary)
No auth needed
Prerequisites: Access to the target system · Ability to execute the fdformat binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_sun
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/138

Scores

EPSS 0.0081
EPSS Percentile 52.3%

Details

Status published
Products (9)
sun/solaris 2.4
sun/solaris 2.5
sun/solaris 2.5.1
sun/solaris 2.6
sun/sunos 5.3
sun/sunos 5.4
sun/sunos 5.5
sun/sunos 5.5.1
sun/sunos 5.7
Published Apr 01, 1997
Tracked Since Feb 18, 2026