Description
Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.
Affected products
- Avaya / call_management_system_server9.0 – 9.0
- Avaya / call_management_system_server11.0 – 11.0
- Avaya / call_management_system_server12.0 – 12.0
- sun / dtmail
- sun / solaris8.0 – 8.0
- sun / solaris9.0 – 9.0
- sun / solaris9.0 – 9.0
- sun / sunos5.8 – 5.8
References
- MISChttp://www.ciac.org/ciac/bulletins/o-202.shtml
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4030
- MISChttp://www.securityfocus.com/bid/11027
- MISChttp://www.idefense.com/application/poi/display?id=132&type=vulnerabilities
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/17095
- MISChttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57627
- MISChttp://www.kb.cert.org/vuls/id/928598