Sun Library Flaw Opens Door to Remote Attacks
A vulnerability in a Sun code library enables a remote attacker to execute code on a user's machine.There is a vulnerability in a Sun Microsystems Inc. code library that enables a remote attacker to execute code on a users machine. The flaw also affects libraries derived from the Sun library, including any BSD-derived libraries with XDR/RPC routines and the GNU C Library with sunrpc. The vulnerability is located in the Sun Network Services Library, which enables developers to incorporate XDR (External Data Representation) into their applications. XDR is a standard for the description and encoding of data and is used to transfer data between computers with different architectures.
Researchers at eEye Digital Security Inc. discovered an integer overflow in the xdrmem_getbytes () function. Depending on the location and use of the vulnerable routine, an attacker may be able to exploit this vulnerability remotely.
Find white papers on security.
For more security news, check out Ziff Davis Medias Security Supersite.