SCO UnixWare 'pkgadd' Local Privilege Escalation Vulnerability
BID:28236
Info
SCO UnixWare 'pkgadd' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 28236 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0310 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 27 2008 12:00AM |
| Updated: | Apr 04 2008 06:59PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SCO Unixware 7.1.4 |
| Not Vulnerable: | |
Discussion
SCO UnixWare 'pkgadd' Local Privilege Escalation Vulnerability
SCO UnixWare 'pkgadd' may allow local attackers to gain elevated privileges. This issue stems from an input-validation error.
Specifically, the utility is prone to a local directory-traversal vulnerability.
A successful exploit can facilitate privilege escalation.
SCO UnixWare 7.1.4 is affected by this issue.
SCO UnixWare 'pkgadd' may allow local attackers to gain elevated privileges. This issue stems from an input-validation error.
Specifically, the utility is prone to a local directory-traversal vulnerability.
A successful exploit can facilitate privilege escalation.
SCO UnixWare 7.1.4 is affected by this issue.
Exploit / POC
SCO UnixWare 'pkgadd' Local Privilege Escalation Vulnerability
An attacker can exploit this issue by using standard filesystem utilities.
The following exploit is available:
An attacker can exploit this issue by using standard filesystem utilities.
The following exploit is available:
Solution / Fix
SCO UnixWare 'pkgadd' Local Privilege Escalation Vulnerability
Solution:
The vendor has released a patch. Please see the references for more information.
SCO Unixware 7.1.4
Solution:
The vendor has released a patch. Please see the references for more information.
SCO Unixware 7.1.4
-
SCO p534589.image
ftp://ftp.sco.com/pub/unixware7/714/security/p534589/p534589.image
References
SCO UnixWare 'pkgadd' Local Privilege Escalation Vulnerability
References:
References:
- UnixWare Product Homepage (Caldera Systems)
- SCO UnixWare pkgadd Directory Traversal Vulnerability (iDefense Labs)