Cray UNICOS NQS Daemon Format String Vulnerability
BID:3590
Info
Cray UNICOS NQS Daemon Format String Vulnerability
| Bugtraq ID: | 3590 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2001 12:00AM |
| Updated: | Nov 28 2001 12:00AM |
| Credit: | This vulnerability was announced in a MICKEY MOUSE HACKING SQUADRON ADVISORY posted to Bugtraq on November 28, 2001. |
| Vulnerable: |
SGI Network Queuing Environment 3.3 .0.16 Cray UNICOS/mk 2.0.5 .54 |
| Not Vulnerable: | |
Discussion
Cray UNICOS NQS Daemon Format String Vulnerability
UNICOS is the supercomputer operating system distributed by Cray. It is typically used with Cray systems.
nqsdaemon doesn't not correctly handle some file names. Upon loading of a shell script by the nqsdaemon that contains format strings, it is possible to execute arbitrary code. Since the nqsdaemon runs as root, the executed code would be in the context of the root user.
This problem makes it possible for local users to gain elevated privileges, and compromise administrative access to a vulnerable system.
UNICOS is the supercomputer operating system distributed by Cray. It is typically used with Cray systems.
nqsdaemon doesn't not correctly handle some file names. Upon loading of a shell script by the nqsdaemon that contains format strings, it is possible to execute arbitrary code. Since the nqsdaemon runs as root, the executed code would be in the context of the root user.
This problem makes it possible for local users to gain elevated privileges, and compromise administrative access to a vulnerable system.
Solution / Fix
Cray UNICOS NQS Daemon Format String Vulnerability
Solution:
SGI has acknowledged the vulnerability in the Network Queuing Environment package, and has stated it will not be providing a patch for the vulnerability. SGI has instead recommended uninstalling the vulnerable package.
Solution:
SGI has acknowledged the vulnerability in the Network Queuing Environment package, and has stated it will not be providing a patch for the vulnerability. SGI has instead recommended uninstalling the vulnerable package.