HP-UX SWVerify Buffer Overflow Vulnerability
BID:3279
Info
HP-UX SWVerify Buffer Overflow Vulnerability
| Bugtraq ID: | 3279 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0979 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 03 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced via the Bugtraq mailing list by <[email protected]> on September 3, 2001. |
| Vulnerable: |
HP HP-UX 11.0 |
| Not Vulnerable: | |
Discussion
HP-UX SWVerify Buffer Overflow Vulnerability
HP-UX is the UNIX Operating System variant distributed by Hewlett-Packard, available for use on systems of size varying from workgroup servers to enterprise systems.
A problem has been discovered in the operating system that can allow a local user to gain elevated privileges. swverify contains a buffer overflow which is exploitable upon receiving 6039 bytes as an argument. The swverify program is setuid root, which allows a local user to execute code as root, potentially gaining administrative access to the vulnerable system.
HP-UX is the UNIX Operating System variant distributed by Hewlett-Packard, available for use on systems of size varying from workgroup servers to enterprise systems.
A problem has been discovered in the operating system that can allow a local user to gain elevated privileges. swverify contains a buffer overflow which is exploitable upon receiving 6039 bytes as an argument. The swverify program is setuid root, which allows a local user to execute code as root, potentially gaining administrative access to the vulnerable system.
Exploit / POC
Solution / Fix
HP-UX SWVerify Buffer Overflow Vulnerability
Solution:
HP has released a fix:
HP HP-UX 11.0
Solution:
HP has released a fix:
HP HP-UX 11.0
-
HP PHCO_23483
http://itrc.hp.com -
HP PHCO_27672
http://itrc.hp.com
References
HP-UX SWVerify Buffer Overflow Vulnerability
References:
References: