Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability

BID:3517

Info

Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability

Bugtraq ID: 3517
Class: Boundary Condition Error
CVE: CVE-2001-0803
Remote: Yes
Local: No
Published: Nov 06 2001 12:00AM
Updated: Nov 05 2007 03:25PM
Credit: This vulnerability was originally discovered by Chris Spencer of the ISS X-Force.
Vulnerable: Xi Graphics Maximum CDE 1.2.3
Xi Graphics DeXtop 2.1
Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 2.6_x86
Sun Solaris 2.6
Sun Solaris 2.5_x86
Sun Solaris 2.5
Sun Solaris 2.4_x86
Sun Solaris 2.4
SGI IRIX 6.5.13
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
SGI IRIX 6.4
SGI IRIX 6.3
SGI IRIX 6.2
SGI IRIX 6.1
Open Group CDE Common Desktop Environment 2.1
+ Sun Solaris 9_x86 Update 2
+ Sun Solaris 9_x86
+ Sun Solaris 9
Open Group CDE Common Desktop Environment 2.0
Open Group CDE Common Desktop Environment 1.2
Open Group CDE Common Desktop Environment 1.1
Open Group CDE Common Desktop Environment 1.0.2
Open Group CDE Common Desktop Environment 1.0.1
IBM AIX 4.3.3
IBM AIX 4.3.2
IBM AIX 4.3.1
IBM AIX 4.3
IBM AIX 4.2.1
IBM AIX 4.2
IBM AIX 4.1.5
IBM AIX 4.1.4
IBM AIX 4.1.3
IBM AIX 4.1.2
IBM AIX 4.1.1
IBM AIX 4.1
IBM AIX 4.0
IBM AIX 5.1
HP HP-UX (VVOS) 11.0.4
HP HP-UX (VVOS) 11.0 4
HP HP-UX (VVOS) 10.24
HP HP-UX 11.11
HP HP-UX 11.0
HP HP-UX 10.20
HP HP-UX 10.10
Compaq Tru64 5.1 a
Compaq Tru64 5.1
Compaq Tru64 5.0 a
Compaq Tru64 5.0
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f
Caldera UnixWare 7
Caldera OpenUnix 8.0
Not Vulnerable:

Exploit / POC

Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

There is information from a highly credible source that an exploit for this vulnerability is currently in use in the wild.

An exploit has been released as part of the MetaSploit Framework 2.3.

Solution / Fix

Multiple Vendor CDE dtspcd Buffer Overflow Vulnerability

Solution:
Vendor fixes are available. Please see the references for details.


Sun Solaris 8_sparc

IBM AIX 5.1

Sun Solaris 2.6

Caldera UnixWare 7

Sun Solaris 2.6_x86

Sun Solaris 7.0

Sun Solaris 7.0_x86

Sun Solaris 8_x86

HP HP-UX 10.10
  • HP PHSS_25785
    http://itrc.hp.com

  • HP Temporary Hotfix: dtspcd.tar.gz
    To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
    ftp://dtspcd:[email protected]/dtspcd.tar.gz


HP HP-UX 10.20
  • HP PHSS_25786
    http://itrc.hp.com

  • HP Temporary Hotfix: dtspcd.tar.gz
    To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
    ftp://dtspcd:[email protected]/dtspcd.tar.gz


HP HP-UX (VVOS) 10.24
  • HP PHSS_26029

  • HP dtspcd.tar.gz
    ftp://dtspcd:[email protected]/dtspcd.tar.gz

  • HP Temporary Hotfix: dtspcd.tar.gz
    To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
    ftp://dtspcd:[email protected]/dtspcd.tar.gz


HP HP-UX 11.0
  • HP PHSS_25787
    http://itrc.hp.com

  • HP PHSS_27869
    http://itrc.hp.com

  • HP Temporary Hotfix: dtspcd.tar.gz
    To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
    ftp://dtspcd:[email protected]/dtspcd.tar.gz


HP HP-UX (VVOS) 11.0 4

HP HP-UX (VVOS) 11.0.4
  • HP Temporary Hotfix: dtspcd.tar.gz
    To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
    ftp://dtspcd:[email protected]/dtspcd.tar.gz


HP HP-UX 11.11
  • HP PHSS_25788
    http://itrc.hp.com

  • HP Temporary Hotfix: dtspcd.tar.gz
    To install this emergency hotfix,download the archive and place it in a protected directory. Verify the integrity of the archive:MD5 Sum: b122f84857f4da65b50d9926201608a1Unpack it, and run 'install_dtspcd x'Where 'x' is either:dtspcd.10.10dtspcd.10.20dtspcd.11.00dtspcd.11.11The value chosen depends
    ftp://dtspcd:[email protected]/dtspcd.tar.gz


Xi Graphics DeXtop 2.1

Sun Solaris 2.5.1 _x86

Sun Solaris 2.5.1

Compaq Tru64 4.0 f

Compaq Tru64 4.0 g

IBM AIX 4.1
  • IBM IX89806


IBM AIX 4.2
  • IBM IX89893


IBM AIX 4.3
  • IBM IX89419


IBM AIX 4.3.3
  • IBM IY06694


Compaq Tru64 5.0 a

Compaq Tru64 5.1 a

Compaq Tru64 5.1

SGI IRIX 6.5

SGI IRIX 6.5.1

SGI IRIX 6.5.10

SGI IRIX 6.5.11

SGI IRIX 6.5.12

SGI IRIX 6.5.13

SGI IRIX 6.5.2

SGI IRIX 6.5.3

SGI IRIX 6.5.4

SGI IRIX 6.5.5

SGI IRIX 6.5.6

SGI IRIX 6.5.7

SGI IRIX 6.5.8

SGI IRIX 6.5.9

Caldera OpenUnix 8.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report