Solaris cachefsd fscache_setup Function Remote Overflow

This script is Copyright (C) 2002-2014 Tenable Network Security, Inc.


Synopsis :

The remote RPC service has multiple buffer overflow vulnerabilities.

Description :

The cachefsd RPC service is running on this port.

Multiple vulnerabilities exist in this service. At least one heap
overflow vulnerability can be exploited remotely to obtain root
privileges by sending a long directory and cache name request to the
service. A buffer overflow can result in root privileges from local
users exploiting the fscache_setup function with a long mount
argument

Solaris 2.5.1, 2.6, 7 and 8 are vulnerable to this issue. Other
operating systems might be affected as well.

*** Nessus did not check for this vulnerability,
*** so this might be a false positive.

See also :

http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0048.html
http://download.oracle.com/sunalerts/1000988.1.html

Solution :

Apply the appropriate patch referenced in the vendor's advisory.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Gain a shell remotely

Nessus Plugin ID: 10951 (cachefsd_overflow.nasl)

Bugtraq ID: 4631

CVE ID: CVE-2002-0084