CVE-2005-2071

Solaris 10 - Local Privilege Escalation via Traceroute Argument Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2071. PoCs published by Przemyslaw Frasunek.

AI-analyzed exploit summary This exploit targets a local buffer overflow vulnerability in Sun Solaris traceroute (CVE-2005-2071) by supplying excessive data through command line arguments. It attempts to execute shellcode via a crafted payload passed to the '-g' option.

Description

traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).

Exploits (1)

exploitdb WORKING POC VERIFIED
by Przemyslaw Frasunek · perllocalsolaris
https://www.exploit-db.com/exploits/25896

This exploit targets a local buffer overflow vulnerability in Sun Solaris traceroute (CVE-2005-2071) by supplying excessive data through command line arguments. It attempts to execute shellcode via a crafted payload passed to the '-g' option.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Sun Solaris traceroute (Solaris 10, x86 platform)
No auth needed
Prerequisites: Local access to the target system · Presence of vulnerable traceroute binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111964580023012&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111963068714114&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111963809801731&w=2
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102060-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015261
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2564
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14049
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17708

Scores

EPSS 0.0106
EPSS Percentile 60.0%

Details

CWE
CWE-264
Status published
Products (1)
sun/solaris 10.0
Published Jun 29, 2005
Tracked Since Feb 18, 2026