VERITAS Cluster Server for UNIX Local Buffer Overflow Vulnerability
BID:15349
Info
VERITAS Cluster Server for UNIX Local Buffer Overflow Vulnerability
| Bugtraq ID: | 15349 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 08 2005 12:00AM |
| Updated: | Nov 08 2005 12:00AM |
| Credit: | Kevin Finisterre discovered this issue. |
| Vulnerable: |
Veritas Software Storage Foundation For UNIX 4.0 Solaris Veritas Software Storage Foundation For UNIX 4.0 Linux Veritas Software Storage Foundation For UNIX 4.0 AIX Veritas Software Storage Foundation For UNIX 3.5 Solaris Veritas Software Storage Foundation For UNIX 3.5 HP-UX Veritas Software Storage Foundation For UNIX 3.4 AIX Veritas Software Storage Foundation For UNIX 2.2 VMWare ESX Veritas Software Storage Foundation For UNIX 2.2 Linux Veritas Software Storage Foundation For Sybase 4.0 Solaris Veritas Software Storage Foundation for Oracle RAC 4.0 Solaris Veritas Software Storage Foundation for Oracle RAC 4.0 Linux Veritas Software Storage Foundation for Oracle RAC 4.0 AIX Veritas Software Storage Foundation for Oracle RAC 3.5 Solaris Veritas Software Storage Foundation For Oracle 4.0 Solaris Veritas Software Storage Foundation For Oracle 4.0 AIX Veritas Software Storage Foundation For Oracle 3.5 Solaris Veritas Software Storage Foundation For Oracle 3.0 AIX Veritas Software Storage Foundation for DB2 4.0 Solaris Veritas Software Storage Foundation for DB2 4.0 AIX Veritas Software Storage Foundation for DB2 1.0 AIX Veritas Software Storage Foundation Cluster File System 4.0 Solaris Veritas Software Storage Foundation Cluster File System 4.0 Linux Veritas Software Storage Foundation Cluster File System 4.0 AIX Veritas Software SANPoint Control Quickstart 3.5 Solaris Veritas Software Cluster Server 4.0 Solaris MP1 Veritas Software Cluster Server 4.0 Solaris BETA Veritas Software Cluster Server 4.0 Solaris Veritas Software Cluster Server 4.0 Linux Beta Veritas Software Cluster Server 4.0 Linux Veritas Software Cluster Server 4.0 AIX Beta Veritas Software Cluster Server 4.0 AIX Veritas Software Cluster Server 3.5 Solaris MP3 Veritas Software Cluster Server 3.5 Solaris MP2 Veritas Software Cluster Server 3.5 Solaris MP1 Veritas Software Cluster Server 3.5 Solaris BETA Veritas Software Cluster Server 3.5 Solaris Veritas Software Cluster Server 3.5 p1 Veritas Software Cluster Server 3.5 MP2 Veritas Software Cluster Server 3.5 MP1J Veritas Software Cluster Server 3.5 MP1 Veritas Software Cluster Server 3.5 HP-UX Update 2 Veritas Software Cluster Server 3.5 HP-UX Update 1 Veritas Software Cluster Server 3.5 HP-UX Veritas Software Cluster Server 3.5 AIX Veritas Software Cluster Server 3.5 Veritas Software Cluster Server 2.2 MP2 Veritas Software Cluster Server 2.2 MP1 Veritas Software Cluster Server 2.2 Linux MP1P1 Veritas Software Cluster Server 2.2 Linux Veritas Software Cluster Server 2.2 |
| Not Vulnerable: |
Veritas Software Cluster Server 4.0 Solaris MP2+ Veritas Software Cluster Server 4.0 Linux MP2+ Veritas Software Cluster Server 4.0 AIX MP2+ Veritas Software Cluster Server 3.5 Solaris P5+ Veritas Software Cluster Server 3.5 HP-UX Update 3+ Veritas Software Cluster Server 3.5 AIX P1+ Veritas Software Cluster Server 2.2 Linux MP2+ |
Discussion
VERITAS Cluster Server for UNIX Local Buffer Overflow Vulnerability
Versions of VERITAS Cluster Server for UNIX are susceptible to a local buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it into an insufficiently sized memory buffer.
This issue allows local attackers to execute arbitrary machine code with superuser credentials, as the affected applications are installed with setuid root privileges.
Versions of VERITAS Cluster Server for UNIX are susceptible to a local buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it into an insufficiently sized memory buffer.
This issue allows local attackers to execute arbitrary machine code with superuser credentials, as the affected applications are installed with setuid root privileges.
Exploit / POC
VERITAS Cluster Server for UNIX Local Buffer Overflow Vulnerability
The following exploit was provided by Kevin Finisterre:
The following exploit was provided by Kevin Finisterre:
Solution / Fix
VERITAS Cluster Server for UNIX Local Buffer Overflow Vulnerability
Solution:
Symantec has released advisory SYM05-023, along with fixes to address this issue. Please see the referenced advisory for information on obtaining fixes.
Solution:
Symantec has released advisory SYM05-023, along with fixes to address this issue. Please see the referenced advisory for information on obtaining fixes.
References
VERITAS Cluster Server for UNIX Local Buffer Overflow Vulnerability
References:
References:
- Cluster Server Page (Veritas)
- DMA[2005-1112a] - 'Veritas Storage Foundation VCSI18N_LANG buffer overflow' (Kevin Finisterre)
- SYM05-023 - VERITAS Cluster Server for UNIX: Local Access Buffer Overflow Vulner (Symantec)
- Veritas SYM05-023 VERITAS Cluster Server for UNIX: Local Access Buffer Overflow (Symantec)