CVE
- Id
- 5274
- CVE No.
- CVE-2002-0884
- Status
- Candidate
- Description
- Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(5) Alderson, Armstrong, Baker, Cole, Frech | MODIFY(1) Jones | NOOP(3) Christey, Cox, Foat
- Comments
- Jones> Suggest description: "...allows remote attackers to execute | arbitrary code via the functions (1) syserr and | (2) error." | Christey> Correction: this is a RARP (Reverse Address Resolution | Protocol) server. | | A colleague of mine with access to Solaris source has noted | that the affected syslog calls can not be fed user-supplied | data, at least for Solaris; if so, then this is not a vulnerability. | Baker> I think you leave the description as it specifies how the attacker is able to execute arbitrary commands.