INFORMATION BULLETIN
| PROBLEM: | A buffer overflow vulnerability exists in the Common Desktop Environment (CDE) DtHelp library which could allow a local user to gain root access or possibly crash affected CDE applications which utilize the DtHelp library causing a Denial of Service. |
| SOFTWARE: | Solaris 7, 8, 9 |
| DAMAGE: | A local user could gain root access. |
| SOLUTION: | Download and apply the appropriate patch. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. A local user could gain root access. |
| LINKS: | |
| CIRC BULLETIN: | http://www.doecirc.energy.gov/bulletins/o-020.shtml |
| ORIGINAL BULLETIN: | Sun Alert ID: 57414 |
| http://au.sunsolve.sun.com/search/document.do?assetkey=1-26-57414-1 | |
| ADDITIONAL LINK: | SGI Security Advisory 20040801-01-P SGI Bug 902695 http://www.sgi.com/support/security/advisories.html |
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CAN-2003-0834 |
REVISION HISTORY:
05/04/2004 - revised to reflect the changes Sun has made in their Sun Alert
ID: 57414 in the State section, Contributing Factors section, Relief/
Workaround section, and Resolution section.
08/05/04 - added a link to SGI Security Advisory 20040801-01-P SGI Bug 902695.
[***** Start Sun Alert ID: 57414 *****]
Sun Alert ID: 57414
Synopsis: Buffer Overflow Vulnerability in the CDE DtHelp Library May Allow Unauthorized "root" Access
Category: Security
Product: Solaris
BugIDs: 4930117
Avoidance: Patch
State: Resolved
Date Released: 07-Nov-2003, 30-Apr-2004
Date Closed: 30-Apr-2004
Date Modified: 06-Feb-2004, 30-Apr-2004
1. Impact
The DtHelp library (libDtHelp.so) is used by the Common Desktop Environment (CDE) to display context help.
This library contains a buffer overflow vulnerability which could allow a local user to gain root access
or possibly crash affected CDE applications which utilize the DtHelp library causing a Denial of Service.
This issue is described in the CERT Vulnerability VU#575804 (see http://www.kb.cert.org/vuls/id/575804)
and CVE CAN-2003-0834 (see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0834).
2. Contributing Factors
This issue can occur in the following releases:
SPARC Platform
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/