Improper input validation in Oracle Solaris - CVE-2020-14871
Published: October 23, 2020 / Updated: December 26, 2021
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Pluggable authentication module (PAM) component in Oracle Solaris. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Note, this vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2020-14871
Links to Public Exploits and PoC-codes
- Exploit #7205 - CVE-2020-14871-Exploit (This is a basic ROP based exploit for CVE 2020-14871. CVE 2020-14871 is a vulnerability in Sun Solaris systems libpam library, and exploitable over ssh) (December 26, 2021)
- Exploit #6478 - Solaris SunSSH 11.0 x86 - libpam Remote Root (3) (June 28, 2021)
- Exploit #5631 - Solaris SunSSH 11.0 x86 - libpam Remote Root (June 17, 2021)
- Exploit #5583 - Solaris SunSSH 11.0 x86 - libpam Remote Root (2) (June 17, 2021)
- Exploit #4944 - Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflow (December 16, 2020)