CDE DTPrintInfo Session Option Buffer Overflow Vulnerability
BID:3487
Info
CDE DTPrintInfo Session Option Buffer Overflow Vulnerability
| Bugtraq ID: | 3487 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 29 2001 12:00AM |
| Updated: | Oct 29 2001 12:00AM |
| Credit: | This vulnerability was announced in an IBM Security Advisory posted to Bugtraq on October 29, 2001, and was initially discovered by SNS. |
| Vulnerable: |
SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 IBM AIX 4.3.3 IBM AIX 4.3.2 IBM AIX 4.3.1 IBM AIX 4.3 IBM AIX 5.1 Compaq Tru64 5.1 a Compaq Tru64 5.1 Compaq Tru64 5.0 a Compaq Tru64 4.0 g Compaq Tru64 4.0 f |
| Not Vulnerable: | |
Solution / Fix
CDE DTPrintInfo Session Option Buffer Overflow Vulnerability
Solution:
Compaq has released a number of fixes which address this and other vulnerabilities.
Vendor updates available:
IBM AIX 5.1
Compaq Tru64 4.0 f
Compaq Tru64 5.1 a
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10 m
SGI IRIX 6.5.11
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13
SGI IRIX 6.5.14
SGI IRIX 6.5.2
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.3
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.6
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9
Solution:
Compaq has released a number of fixes which address this and other vulnerabilities.
Vendor updates available:
IBM AIX 5.1
-
IBM IY25504
http://www.ibm.com/support
Compaq Tru64 4.0 f
-
Compaq DUV40FB18-C0067301-13427-ES-20020228.tar
Prerequisite: 4.0F with Patch Kit 7 (BL18) installed
http://ftp1.support.compaq.com/public/unix/v4.0f/
Compaq Tru64 5.1 a
-
Compaq T64V51AB1-C0011201-13438-ES-20020228.tar
Prerequisite: 5.1A with Patch Kit 1 (BL1) installed
http://ftp1.support.compaq.com/public/unix/v5.1a/
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10 m
SGI IRIX 6.5.11
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13
SGI IRIX 6.5.14
SGI IRIX 6.5.2
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.3
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.6
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9