Veritas Cluster Server Superuser Compromise Vulnerability
BID:11421
Info
Veritas Cluster Server Superuser Compromise Vulnerability
| Bugtraq ID: | 11421 |
| Class: | Unknown |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Oct 15 2004 12:00AM |
| Updated: | Oct 15 2004 12:00AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Veritas Software Cluster Server 4.0 Solaris BETA Veritas Software Cluster Server 4.0 Solaris Veritas Software Cluster Server 4.0 Linux Beta Veritas Software Cluster Server 4.0 Linux Veritas Software Cluster Server 4.0 AIX Beta Veritas Software Cluster Server 4.0 AIX Veritas Software Cluster Server 3.5.1 AIX Veritas Software Cluster Server 3.5 Solaris MP3 Veritas Software Cluster Server 3.5 Solaris MP2 Veritas Software Cluster Server 3.5 Solaris MP1 Veritas Software Cluster Server 3.5 Solaris BETA Veritas Software Cluster Server 3.5 Solaris Veritas Software Cluster Server 3.5 p1 Veritas Software Cluster Server 3.5 MP2 Veritas Software Cluster Server 3.5 MP1J Veritas Software Cluster Server 3.5 MP1 Veritas Software Cluster Server 3.5 HP-UX Update 2 Veritas Software Cluster Server 3.5 HP-UX Update 1 Veritas Software Cluster Server 3.5 HP-UX Veritas Software Cluster Server 3.5 AIX Veritas Software Cluster Server 3.5 Veritas Software Cluster Server 2.2 MP2 Veritas Software Cluster Server 2.2 MP1 Veritas Software Cluster Server 2.2 Linux MP1P1 Veritas Software Cluster Server 2.2 Linux Veritas Software Cluster Server 2.2 Veritas Software Cluster Server 2.1 Linux P1 Veritas Software Cluster Server 2.1 Linux Veritas Software Cluster Server 2.1 Veritas Software Cluster Server 2.0 Solaris GA Veritas Software Cluster Server 2.0 Solaris BETA Veritas Software Cluster Server 2.0 Solaris Veritas Software Cluster Server 2.0 P4 Veritas Software Cluster Server 2.0 P3 Veritas Software Cluster Server 2.0 P2 Veritas Software Cluster Server 2.0 P1 Veritas Software Cluster Server 2.0 Linux Veritas Software Cluster Server 2.0 AIX Veritas Software Cluster Server 2.0 Veritas Software Cluster Server 1.3.1 P3 Veritas Software Cluster Server 1.3.1 HP-UX Veritas Software Cluster Server 1.3 Solaris PRE-GA Veritas Software Cluster Server 1.3 Solaris Veritas Software Cluster Server 1.3 p4 Veritas Software Cluster Server 1.3 P3 Veritas Software Cluster Server 1.3 P2 Veritas Software Cluster Server 1.3 P1 Veritas Software Cluster Server 1.3 NT Veritas Software Cluster Server 1.3 HP-UX Veritas Software Cluster Server 1.3 Veritas Software Cluster Server 1.2 NT Veritas Software Cluster Server 1.1.2 Solaris Veritas Software Cluster Server 1.1.1 Solaris Veritas Software Cluster Server 1.1 Solaris Veritas Software Cluster Server 1.0.2 Solaris Veritas Software Cluster Server 1.0.1 Solaris |
| Not Vulnerable: |
Veritas Software Cluster Server 4.0 Solaris MP1 |
Discussion
Veritas Cluster Server Superuser Compromise Vulnerability
Veritas Cluster Server is affected by a superuser compromise vulnerability. The underlying cause for this issue is currently unknown.
An attacker can leverage this issue to gain superuser access to an affected computer, facilitating privileged unauthorized access. It is currently not known if this issue is remotely or locally exploitable; this BID will be updated as more details are released.
Veritas Cluster Server is affected by a superuser compromise vulnerability. The underlying cause for this issue is currently unknown.
An attacker can leverage this issue to gain superuser access to an affected computer, facilitating privileged unauthorized access. It is currently not known if this issue is remotely or locally exploitable; this BID will be updated as more details are released.
Exploit / POC
Veritas Cluster Server Superuser Compromise Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Veritas Cluster Server Superuser Compromise Vulnerability
Solution:
The vendor has released an advisory dealing with this issue. Please see the referenced advisory for more information.
Veritas Software Cluster Server 1.3 Solaris
Veritas Software Cluster Server 2.2 MP2
Veritas Software Cluster Server 3.5 HP-UX Update 2
Veritas Software Cluster Server 3.5 MP1
Veritas Software Cluster Server 3.5 Solaris MP3
Solution:
The vendor has released an advisory dealing with this issue. Please see the referenced advisory for more information.
Veritas Software Cluster Server 1.3 Solaris
-
Veritas Software vcs.130-patch03_239344.tar.Z
http://ftp.support.veritas.com/pub/support/products/ClusterServer_UNIX /vcs.130-patch03_239344.tar.Z
Veritas Software Cluster Server 2.2 MP2
-
Veritas Software vcs.2.2_MP2_i147547a.esx_210_i686.tar_271277.gz
http://seer.support.veritas.com/docs/271277.htm -
Veritas Software vcs.2.2_MP2_i147547a.rhel_21_i686.tar_270095.gz
http://seer.support.veritas.com/docs/270095.htm -
Veritas Software vcs.2.2_MP2_i147547a.rhel_30_i686.tar_270096.gz
http://seer.support.veritas.com/docs/270096.htm -
Veritas Software vcs.2.2_MP2_i147547a.rhel_30_u2_ia64.tar_270097.gz
http://seer.support.veritas.com/docs/270097.htm -
Veritas Software vcs.2.2_MP2_i147547a.sles8_sp3_i686.tar_270092.gz
http://seer.support.veritas.com/docs/270092.htm
Veritas Software Cluster Server 3.5 HP-UX Update 2
-
Veritas Software vcs.3.5P1+i147547b.hp_270074.tar.Z
http://seer.support.veritas.com/docs/270074.htm
Veritas Software Cluster Server 3.5 MP1
-
Veritas Software vcs.3.5P1+i147547b.aix_270090.tar.Z
http://seer.support.veritas.com/docs/270090.htm
Veritas Software Cluster Server 3.5 Solaris MP3
-
Veritas Software vcs.3.5P3+i147547a.sol_270071.tar.Z
http://seer.support.veritas.com/docs/270071.htm
References
Veritas Cluster Server Superuser Compromise Vulnerability
References:
References:
- A security flaw which allows for potential unauthorized root access in VERITAS (Veritas Software)
- Veritas Homepage (Veritas Software)