CVE-2001-0426
Solaris - Local Privilege Escalation via LANG Environment Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-0426. PoCs published by Last Stage of Delirium.
AI-analyzed exploit summary This exploit targets a buffer overflow in the CDE Session Manager 'dtsession' via the LANG environment variable, allowing arbitrary code execution as root due to the setuid binary. It uses shellcode to spawn a root shell and is designed for x86 Solaris systems.
Description
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
Exploits (1)
This exploit targets a buffer overflow in the CDE Session Manager 'dtsession' via the LANG environment variable, allowing arbitrary code execution as root due to the setuid binary. It uses shellcode to spawn a root shell and is designed for x86 Solaris systems.