Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability

BID:3382

Info

Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability

Bugtraq ID: 3382
Class: Input Validation Error
CVE: CVE-2001-0717
Remote: Yes
Local: No
Published: Oct 02 2001 12:00AM
Updated: Apr 18 2006 11:36PM
Credit: Discovered by ISS X-Force.
Vulnerable: Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 2.6_x86
Sun Solaris 2.6
Sun Solaris 2.5_x86
Sun Solaris 2.5
SGI IRIX 6.5.17
SGI IRIX 6.5.16
SGI IRIX 6.5.15
SGI IRIX 6.5.14
SGI IRIX 6.5.13
SGI IRIX 6.4
SGI IRIX 6.3
SGI IRIX 6.2
SGI IRIX 6.1
SGI IRIX 6.0.1
SGI IRIX 6.0
SGI IRIX 5.3
SGI IRIX 5.2
IBM AIX 4.3.3
IBM AIX 4.3.2
IBM AIX 4.3.1
IBM AIX 4.3
IBM AIX 5.1
HP HP-UX (VVOS) 11.0 4
HP HP-UX (VVOS) 10.24
HP HP-UX 11.11
HP HP-UX 11.0
HP HP-UX 10.20
HP HP-UX 10.10
Compaq Tru64 5.1
Compaq Tru64 5.0 a
Compaq Tru64 4.0 g
Compaq Digital Unix 4.0 f
Caldera UnixWare 7
Caldera OpenUnix 8.0
Not Vulnerable: SGI IRIX 6.5.19
SGI IRIX 6.5.18

Discussion

Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability

CDE ships with a daemon called the ToolTalk database server, which allows programs designed for use in CDE to communicate with each other. The server is enabled by default on most systems shipped with CDE.

ToolTalk database server contains a remotely exploitable format-string vulnerability.

Remote attackers may be able to cause a denial of service or gain root access on the target host.

Exploit / POC

Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability

CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

Solution / Fix

Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability

Solution:
Administrators are highly advised to disable the service until fixes are available. This may involve renaming/removing the startup script in the appropriate directory. Administrators should also ensure that the service is not running and should kill the process if it is.

HP has released fixes for some versions of HP-UX.

IBM has released a temporary hotfix.

Compaq has released fixes for Digital Unix/Tru64.

Sun has released fixes.

Caldera has released a fix for OpenUnix and Unixware.

SGI has released an updated advisory (Security Bulletin 20021102-02-P) and fixes that address an issue discovered in the fixes found in Security Bulletin 20021102-01-P.


Sun Solaris 2.5_x86
  • Sun 105495-10


Caldera UnixWare 7

Sun Solaris 8_sparc
  • Sun 110286-04


Sun Solaris 2.6_x86
  • Sun 105803-18


Sun Solaris 2.5
  • Sun 104428-12


Sun Solaris 7.0
  • Sun 107893-15


IBM AIX 5.1

Sun Solaris 7.0_x86
  • Sun 107894-14


Sun Solaris 2.6
  • Sun 105802-16


Sun Solaris 8_x86
  • Sun 110287-04


HP HP-UX 10.10
  • HP PHSS_25136


HP HP-UX 10.20
  • HP PHSS_25137


HP HP-UX (VVOS) 10.24
  • HP PHSS_25419


HP HP-UX 11.0
  • HP PHSS_25138


HP HP-UX (VVOS) 11.0 4
  • HP PHSS_25420


HP HP-UX 11.11

Sun Solaris 2.5.1
  • Sun 104489-14


Sun Solaris 2.5.1 _x86
  • Sun 105496-12


Compaq Tru64 4.0 g
  • Compaq T64V40GAS0003-20010613.tar


Compaq Digital Unix 4.0 f
  • Compaq DUV40FAS0006-20010620.tar


IBM AIX 4.3

IBM AIX 4.3.1

IBM AIX 4.3.2

IBM AIX 4.3.3

Compaq Tru64 5.0 a
  • Compaq T64V50AAS0003-20010523.tar


Compaq Tru64 5.1
  • Compaq T64V51AS0003-20010413.tar


SGI IRIX 6.5.13

SGI IRIX 6.5.14

SGI IRIX 6.5.15

SGI IRIX 6.5.16

SGI IRIX 6.5.17

Caldera OpenUnix 8.0

References

Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report