20021125 Solaris fs.auto Remote Compromise VulnerabilityThird-party advisory
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21541 CVE-2002-1317
XFree86 X11R6 3.3.x - Font Server Remote Buffer Overrun
Record summary
CVE-2002-1317 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBXFree86 X11R6 3.3.x - Font Server Remote Buffer OverrunExploitDB exploitby TESO SecurityNot analyzed1 file
References
Showing 12 of 1320021125 ISS Security Brief: Solaris fs.auto Remote Compromise Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=103825150527843&w=2 sunsolve.sun.comConfirmation
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/48879 CA-2002-34Third-party advisory
http://www.cert.org/advisories/CA-2002-34.html N-024Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/n-024.shtml solaris-fsauto-execute-code(10375)vdb entry
http://www.iss.net/security_center/static/10375.php VU#312313Third-party advisory
http://www.kb.cert.org/vuls/id/312313 HPSBUX0212-228Vendor advisory
http://www.securityfocus.com/advisories/4988 6241vdb entry
http://www.securityfocus.com/bid/6241 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1317 oval:org.mitre.oval:def:149vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A149 oval:org.mitre.oval:def:152vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A152