CVE-2002-0033

Solaris - Remote Code Execution via cfsd_calloc Heap Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0033. PoCs published by Last Stage of Delirium.

AI-analyzed exploit summary This exploit targets a buffer overflow in cachefsd on Solaris 2.6/2.7 SPARC systems, leveraging heap manipulation to achieve remote code execution. It uses brute-force techniques to locate the correct memory address and injects shellcode to spawn a root shell.

Description

Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Last Stage of Delirium · cremotesolaris
https://www.exploit-db.com/exploits/21437

This exploit targets a buffer overflow in cachefsd on Solaris 2.6/2.7 SPARC systems, leveraging heap manipulation to achieve remote code execution. It uses brute-force techniques to locate the correct memory address and injects shellcode to spawn a root shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: cachefsd on Solaris 2.6/2.7
No auth needed
Prerequisites: Network access to the target system · cachefsd service running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Patch, Vendor Advisory x_refsource_confirm
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A124
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/635811
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2002-11.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4674
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A31
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-05/0026.html
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8999.php

Scores

EPSS 0.2308
EPSS Percentile 97.5%

Details

Status published
Products (5)
sun/solaris 2.5.1 (2 CPE variants)
sun/solaris 2.6
sun/solaris 7.0 (2 CPE variants)
sun/solaris 8.0 (2 CPE variants)
sun/sunos
Published May 29, 2002
Tracked Since Feb 18, 2026