Vulnerabilities > CVE-2001-0652 - Heap Overflow vulnerability in Solaris xlock

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
sun
exploit available

Summary

Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.

Exploit-Db

  • descriptionSolaris 8 x86 xlock Heap Overflow Vulnerability. CVE-2001-0652. Local exploit for solaris platform
    idEDB-ID:21059
    last seen2016-02-02
    modified2001-08-10
    published2001-08-10
    reporterNsfocus
    sourcehttps://www.exploit-db.com/download/21059/
    titleSolaris 8 x86 xlock Heap Overflow Vulnerability
  • descriptionSolaris 2.6/7/8 SPARC xlock Heap Overflow Vulnerability. CVE-2001-0652. Local exploit for solaris platform
    idEDB-ID:21058
    last seen2016-02-02
    modified2001-08-10
    published2001-08-10
    reporterNsfocus
    sourcehttps://www.exploit-db.com/download/21058/
    titleSolaris 2.6/7/8 SPARC xlock Heap Overflow Vulnerability

Oval

  • accepted2018-09-11T10:00:00.000-05:00
    classvulnerability
    contributors
    nameDavid Proulx
    organizationThe MITRE Corporation
    descriptionHeap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.
    familyunix
    idoval:org.mitre.oval:def:10
    statusaccepted
    submitted2002-09-17T12:00:00.000-04:00
    titleHeap Overflow in Solaris 8 xlock
    version35
  • accepted2016-02-08T10:00:00.000-05:00
    classvulnerability
    contributors
    nameDavid Proulx
    organizationThe MITRE Corporation
    descriptionHeap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.
    familyunix
    idoval:org.mitre.oval:def:131
    statusaccepted
    submitted2002-10-17T12:00:00.000-04:00
    titleHeap Overflow in Solaris 7 xlock
    version35