CVE-2002-0090
Description
Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:o:sun:solaris:8.0:*:x86:*:*:*:*:*
- Range: Solaris 8
Patches
Vulnerability mechanics
Root cause
"Buffer overflow in ConnectToServer due to insufficient bounds checking on the display command line option."
Attack vector
A local attacker triggers the bug by passing a long display command line option to the lbxproxy binary. The `ConnectToServer` function in `lbxproxy/di/wire.c` fails to properly bounds-check the input, leading to a buffer overflow. The attacker can then execute arbitrary code with root privileges [ref_id=1].
Affected code
The vulnerability is in the `ConnectToServer` function within `lbxproxy/di/wire.c` of the Low BandWidth X proxy (lbxproxy) component of XFree86. The advisory does not specify the exact line or the nature of the buffer overflow beyond its location in this function.
What the fix does
The advisory does not include a patch. It directs users to consult vendor information from Sun Microsystems for a solution. Without a published fix, the recommended remediation would be to apply vendor-supplied patches or disable the lbxproxy service if not needed.
Preconditions
- authThe attacker must have local access to the system to run the lbxproxy binary.
- inputThe attacker must supply a long display command line option to trigger the overflow.
Generated on Jun 17, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
9- www.esecurityonline.com/advisories/eSO3761.aspnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/188507nvdThird Party AdvisoryUS Government Resource
- archives.neohapsis.com/archives/vulnwatch/2002-q2/0041.htmlnvd
- online.securityfocus.com/archive/1/270149nvd
- sunsolve.sun.com/pub-cgi/retrieve.plnvd
- www.iss.net/security_center/static/8958.phpnvd
- www.securityfocus.com/bid/4633nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A179nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A86nvd
News mentions
0No linked articles in our index yet.