HP-UX Local X Font Server Buffer Overflow Vulnerability
BID:10551
Info
HP-UX Local X Font Server Buffer Overflow Vulnerability
| Bugtraq ID: | 10551 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 15 2004 12:00AM |
| Updated: | Jun 15 2004 12:00AM |
| Credit: | Discovery of this issue is credited to watercloud. |
| Vulnerable: |
HP HP-UX 11.23 HP HP-UX 11.22 HP HP-UX 11.20 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.34 HP HP-UX 10.30 HP HP-UX 10.26 HP HP-UX 10.24 HP HP-UX 10.20 SIS HP HP-UX 10.20 Series 800 HP HP-UX 10.20 Series 700 HP HP-UX 10.20 HP HP-UX 10.16 HP HP-UX 10.10 HP HP-UX 10.9 HP HP-UX 10.8 HP HP-UX 10.1 0 HP HP-UX 10.0 1 HP HP-UX 10.0 HP HP-UX 9.10 HP HP-UX 9.9 HP HP-UX 9.8 HP HP-UX 9.7 HP HP-UX 9.6 HP HP-UX 9.5 HP HP-UX 9.4 HP HP-UX 9.3 HP HP-UX 9.1 HP HP-UX 9.0 HP HP-UX 8.9 HP HP-UX 8.8 HP HP-UX 8.7 HP HP-UX 8.6 HP HP-UX 8.5 HP HP-UX 8.4 HP HP-UX 8.2 HP HP-UX 8.1 HP HP-UX 8.0 HP HP-UX 7.8 HP HP-UX 7.6 HP HP-UX 7.4 HP HP-UX 7.2 HP HP-UX 7.0 HP HP-UX 11i v1 |
| Not Vulnerable: | |
Discussion
HP-UX Local X Font Server Buffer Overflow Vulnerability
HP-UX X Font Server is reportedly affected by a local buffer overflow vulnerability. This issue is due to a failure of the application to properly validate the length of a user-supplied string before copying it into a finite buffer.
This issue may result in corruption of the affected application's memory space. This may be exploited to manipulate the execution flow of the vulnerable application, allowing for the execution of arbitrary machine code with the privileges of the 'bin' group.
HP-UX X Font Server is reportedly affected by a local buffer overflow vulnerability. This issue is due to a failure of the application to properly validate the length of a user-supplied string before copying it into a finite buffer.
This issue may result in corruption of the affected application's memory space. This may be exploited to manipulate the execution flow of the vulnerable application, allowing for the execution of arbitrary machine code with the privileges of the 'bin' group.
Exploit / POC
HP-UX Local X Font Server Buffer Overflow Vulnerability
The following exploit has been provided:
The following exploit has been provided:
Solution / Fix
HP-UX Local X Font Server Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
HP-UX Local X Font Server Buffer Overflow Vulnerability
References:
References:
- HP-UX Homepage (HP)
- Welcome to Hewlett Packard (Hewlett Packard)