HP-UX Software Distributor SWAsk Local Format String Vulnerability
BID:20726
Info
HP-UX Software Distributor SWAsk Local Format String Vulnerability
| Bugtraq ID: | 20726 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2574 CVE-2006-5558 |
| Remote: | No |
| Local: | Yes |
| Published: | May 24 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | NCC Group is credited with the discovery of this vulnerability. |
| Vulnerable: |
HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.04 HP HP-UX B.11.00 Avaya Predictive Dialer 0 |
| Not Vulnerable: | |
Discussion
HP-UX Software Distributor SWAsk Local Format String Vulnerability
HP-UX is prone to a local format-string vulnerability because it fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
A local attacker may exploit this issue to execute arbitrary machine code in the context of the affected application. Since the application executes by default with superuser privileges, successfully exploiting this issue will result in a computer compromise.
This issue was originally disclosed as part of BID 18098 (HP-UX Software Distributor Unspecified Local Privilege Escalation Vulnerability), but has been assigned a separate record because of new information.
HP-UX is prone to a local format-string vulnerability because it fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
A local attacker may exploit this issue to execute arbitrary machine code in the context of the affected application. Since the application executes by default with superuser privileges, successfully exploiting this issue will result in a computer compromise.
This issue was originally disclosed as part of BID 18098 (HP-UX Software Distributor Unspecified Local Privilege Escalation Vulnerability), but has been assigned a separate record because of new information.
Exploit / POC
HP-UX Software Distributor SWAsk Local Format String Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
HP-UX Software Distributor SWAsk Local Format String Vulnerability
Solution:
The vendor has released security advisory HPSBUX02114 (SSRT061115 rev.1 - HP-UX Running Software Distributor Local Elevation of Privilege) to address this issue.
HP HP-UX B.11.11
HP HP-UX B.11.23
HP HP-UX B.11.04
HP HP-UX B.11.00
Solution:
The vendor has released security advisory HPSBUX02114 (SSRT061115 rev.1 - HP-UX Running Software Distributor Local Elevation of Privilege) to address this issue.
HP HP-UX B.11.11
-
HP PHCO_34539
http://itrc.hp.com
HP HP-UX B.11.23
-
HP B.11.23.0606.045
http://itrc.hp.com
HP HP-UX B.11.04
-
HP PHCO_34814
http://itrc.hp.com
HP HP-UX B.11.00
-
HP PHCO_34568
http://itrc.hp.com
References
HP-UX Software Distributor SWAsk Local Format String Vulnerability
References:
References: