Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability
BID:3517
Info
Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability
| Bugtraq ID: | 3517 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0803 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2001 12:00AM |
| Updated: | Nov 05 2007 03:25PM |
| Credit: | This vulnerability was originally discovered by Chris Spencer of the ISS X-Force. |
| Vulnerable: |
Xi Graphics Maximum CDE 1.2.3 Xi Graphics DeXtop 2.1 Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 _ppc Sun Solaris 2.5.1 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 Open Group CDE Common Desktop Environment 2.1 Open Group CDE Common Desktop Environment 2.0 Open Group CDE Common Desktop Environment 1.2 Open Group CDE Common Desktop Environment 1.1 Open Group CDE Common Desktop Environment 1.0.2 Open Group CDE Common Desktop Environment 1.0.1 IBM AIX 4.3.3 IBM AIX 4.3.2 IBM AIX 4.3.1 IBM AIX 4.3 IBM AIX 4.2.1 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 IBM AIX 4.0 IBM AIX 5.1 HP HP-UX (VVOS) 11.0.4 HP HP-UX (VVOS) 11.0 4 HP HP-UX (VVOS) 10.24 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.20 HP HP-UX 10.10 Compaq Tru64 5.1 a Compaq Tru64 5.1 Compaq Tru64 5.0 a Compaq Tru64 5.0 Compaq Tru64 4.0 g Compaq Tru64 4.0 f Caldera UnixWare 7 Caldera OpenUnix 8.0 |
| Not Vulnerable: | |
Exploit / POC
Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
There is information from a highly credible source that an exploit for this vulnerability is currently in use in the wild.
An exploit has been released as part of the MetaSploit Framework 2.3.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
There is information from a highly credible source that an exploit for this vulnerability is currently in use in the wild.
An exploit has been released as part of the MetaSploit Framework 2.3.
Solution / Fix
Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability
Solution:
Vendor fixes are available. Please see the references for details.
Sun Solaris 8_sparc
IBM AIX 5.1
Sun Solaris 2.6
Caldera UnixWare 7
Sun Solaris 2.6_x86
Sun Solaris 7.0
Sun Solaris 7.0_x86
Sun Solaris 8_x86
HP HP-UX 10.10
HP HP-UX 10.20
HP HP-UX (VVOS) 10.24
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0 4
HP HP-UX (VVOS) 11.0.4
HP HP-UX 11.11
Xi Graphics DeXtop 2.1
Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1
Compaq Tru64 4.0 f
Compaq Tru64 4.0 g
IBM AIX 4.1
IBM AIX 4.2
IBM AIX 4.3
IBM AIX 4.3.3
Compaq Tru64 5.0 a
Compaq Tru64 5.1 a
Compaq Tru64 5.1
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.11
SGI IRIX 6.5.12
SGI IRIX 6.5.13
SGI IRIX 6.5.2
SGI IRIX 6.5.3
SGI IRIX 6.5.4
SGI IRIX 6.5.5
SGI IRIX 6.5.6
SGI IRIX 6.5.7
SGI IRIX 6.5.8
SGI IRIX 6.5.9
Caldera OpenUnix 8.0
Solution:
Vendor fixes are available. Please see the references for details.
Sun Solaris 8_sparc
-
Sun 108949-07
http://sunsolve.sun.com
IBM AIX 5.1
-
IBM IY25437
http://www.ibm.com/support
Sun Solaris 2.6
-
Sun 105669-11
http://sunsolve.sun.com
Caldera UnixWare 7
-
Caldera erg711881.Z
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/erg7118 81.Z
Sun Solaris 2.6_x86
-
Sun 105670-10
http://sunsolve.sun.com
Sun Solaris 7.0
-
Sun 106934-04
http://sunsolve.sun.com
Sun Solaris 7.0_x86
-
Sun 106935-04
http://sunsolve.sun.com
Sun Solaris 8_x86
-
Sun 108950-07
http://sunsolve.sun.com
HP HP-UX 10.10
-
HP PHSS_25785
http://itrc.hp.com -
HP Temporary Hotfix: dtspcd.tar.gz
To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
ftp://dtspcd:[email protected]/dtspcd.tar.gz
HP HP-UX 10.20
-
HP PHSS_25786
http://itrc.hp.com -
HP Temporary Hotfix: dtspcd.tar.gz
To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
ftp://dtspcd:[email protected]/dtspcd.tar.gz
HP HP-UX (VVOS) 10.24
-
HP PHSS_26029
-
HP dtspcd.tar.gz
ftp://dtspcd:[email protected]/dtspcd.tar.gz -
HP Temporary Hotfix: dtspcd.tar.gz
To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
ftp://dtspcd:[email protected]/dtspcd.tar.gz
HP HP-UX 11.0
-
HP PHSS_25787
http://itrc.hp.com -
HP PHSS_27869
http://itrc.hp.com -
HP Temporary Hotfix: dtspcd.tar.gz
To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
ftp://dtspcd:[email protected]/dtspcd.tar.gz
HP HP-UX (VVOS) 11.0 4
-
HP PHSS_26030
-
HP dtspcd.tar.gz
ftp://dtspcd:[email protected]/dtspcd.tar.gz
HP HP-UX (VVOS) 11.0.4
-
HP Temporary Hotfix: dtspcd.tar.gz
To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
ftp://dtspcd:[email protected]/dtspcd.tar.gz
HP HP-UX 11.11
-
HP PHSS_25788
http://itrc.hp.com -
HP Temporary Hotfix: dtspcd.tar.gz
To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
ftp://dtspcd:[email protected]/dtspcd.tar.gz
Xi Graphics DeXtop 2.1
-
Xi Graphics DEX2100.012.tar.gz
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.012.tar.gz
Sun Solaris 2.5.1 _x86
-
Sun 108364-02
http://sunsolve.sun.com
Sun Solaris 2.5.1
-
Sun 108363-02
http://sunsolve.sun.com
Compaq Tru64 4.0 f
-
Compaq DUV40FB18-C0067301-13427-ES-20020228.tar
Prerequisite: 4.0F with Patch Kit 7 (BL18) installed
http://ftp1.support.compaq.com/public/unix/v4.0f/
Compaq Tru64 4.0 g
-
Compaq t64v40gb17-c0010301-13400-es-20020226.tar
http://ftp1.support.compaq.com/public/unix/v4.0g/
IBM AIX 4.1
IBM AIX 4.2
IBM AIX 4.3
IBM AIX 4.3.3
Compaq Tru64 5.0 a
-
Compaq t64v50ab17-c0018301-13396-es-20020226.tar
http://ftp1.support.compaq.com/public/unix/v5.0a/
Compaq Tru64 5.1 a
-
Compaq T64V51AB1-C0011201-13438-ES-20020228.tar
Prerequisite: 5.1A with Patch Kit 1 (BL1) installed
http://ftp1.support.compaq.com/public/unix/v5.1a/
Compaq Tru64 5.1
-
Compaq t64v51b18-c0102001-13428-es-20020228.tar
http://ftp1.support.compaq.com/public/unix/v5.1/
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.11
SGI IRIX 6.5.12
SGI IRIX 6.5.13
-
SGI 4416
ftp://patches.sgi.com/support/free/security/patches/ -
SGI 4869
ftp://patches.sgi.com/
SGI IRIX 6.5.2
SGI IRIX 6.5.3
SGI IRIX 6.5.4
SGI IRIX 6.5.5
SGI IRIX 6.5.6
SGI IRIX 6.5.7
SGI IRIX 6.5.8
SGI IRIX 6.5.9
Caldera OpenUnix 8.0
-
Caldera erg711881.Z
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/erg7118 81.Z