Multiple Vendor libXt library Vulnerability
BID:237
Info
Multiple Vendor libXt library Vulnerability
| Bugtraq ID: | 237 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 1997 12:00AM |
| Updated: | Aug 25 1997 12:00AM |
| Credit: | This vulnerability was originally posted to the Bugtraq mailing list by Bloodmask ([email protected]) Tue, 13 Aug 1996. Lengthy discussion followed. |
| Vulnerable: |
Sun SunOS 4.1.4 Sun SunOS 4.1.3 _U1 Sun SunOS 4.1.3 Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 Sun Solaris 2.3 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0 SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.0 SGI IRIX 4.0 NEC UX/4800 (64) NEC UP-UX/V (Rel4.2MP) NEC Ews-Ux V (Rel4.2MP) NEC Ews-Ux V (Rel4.2) IBM AIX 4.2 IBM AIX 4.1 IBM AIX 3.2 HP HP-UX (VVOS) 10.24 HP HP-UX 10.34 HP HP-UX 10.30 HP HP-UX 10.20 HP HP-UX 10.16 HP HP-UX 10.10 HP HP-UX 10.9 HP HP-UX 10.8 HP HP-UX 10.1 0 HP HP-UX 10.0 HP HP-UX 9.10 HP HP-UX 9.1 HP HP-UX 9.0 FreeBSD FreeBSD 2.0 FreeBSD FreeBSD 1.1.5 .1 Caldera UnixWare 7.1 .0 Caldera UnixWare 7 BSDI BSD/OS 2.1 BSDI BSD/OS 2.0.1 BSDI BSD/OS 2.0 |
| Not Vulnerable: |
Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SGI IRIX 6.5 SGI IRIX 6.4 HP HP-UX 11.0 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.1.7 .1 FreeBSD FreeBSD 2.1.6 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 BSDI BSD/OS 4.0 BSDI BSD/OS 3.0 |
Discussion
Multiple Vendor libXt library Vulnerability
The libXt library is part of the X Windows system. There are several buffer overflow conditions that may allow an unauthorized user to gain root privileges through setuid and setgid programs that are linked to libXt. These problems were openly discussed on the Bugtraq mailing list in 1996, this discussion led the OpenGroup (maintainers of the X-Windowing System) to release a new version of X Windows which was more thoroughly audited and which hopefully addressed a series of buffer overflows.
The libXt library is part of the X Windows system. There are several buffer overflow conditions that may allow an unauthorized user to gain root privileges through setuid and setgid programs that are linked to libXt. These problems were openly discussed on the Bugtraq mailing list in 1996, this discussion led the OpenGroup (maintainers of the X-Windowing System) to release a new version of X Windows which was more thoroughly audited and which hopefully addressed a series of buffer overflows.
Exploit / POC
Multiple Vendor libXt library Vulnerability
Exploits dtterm-exploit.c and xterm-exploit.c contributed by jGgM <[email protected]> for UnixWare 7.1 and 7.0:
Exploits dtterm-exploit.c and xterm-exploit.c contributed by jGgM <[email protected]> for UnixWare 7.1 and 7.0:
Solution / Fix
Multiple Vendor libXt library Vulnerability
Solution:
A series of Vendor solutions are available in the attached messages and FIRST/Vendor advisories. Please see the Credit section.
Solution:
A series of Vendor solutions are available in the attached messages and FIRST/Vendor advisories. Please see the Credit section.
References
Multiple Vendor libXt library Vulnerability
References:
References:
- HP Electronic Support Center for Europe (Hewlett Packard)
- HP Electronic Support Center for US, Canada, Asia-Pacific, & Latin-America (Hewlett Packard)
- IBM Support Databases (IBM)
- Sun Patch Access Page (Sun Microsystems)
- Sun Patches List (Sun Microsystems)
- Sunsolve Online(tm) (Sun Microsystems)