Caldera UnixWare Message Catalog Environment Variable Format String Vulnerability
BID:4060
Info
Caldera UnixWare Message Catalog Environment Variable Format String Vulnerability
| Bugtraq ID: | 4060 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2002 12:00AM |
| Updated: | Feb 07 2002 12:00AM |
| Credit: | This vulnerability was discovered by JeGalGhongMyeung <[email protected]>. |
| Vulnerable: |
Caldera UnixWare 7.1.1 |
| Not Vulnerable: | |
Discussion
Caldera UnixWare Message Catalog Environment Variable Format String Vulnerability
UnixWare is a commercially available Unix Operating System. It was originally developed by SCO, and is now distributed and maintained by Caldera.
A format string vulnerability in the locale subsystem could lead to a user gaining elevated privileges. A local user could potentially supply maliciously crafted message catalogs through the LC_MESSAGES environment variable. This could allow a local user to load arbitrary message catalogs into setuid or setgid programs, and execute arbitrary code with setuid/setgid privileges.
UnixWare is a commercially available Unix Operating System. It was originally developed by SCO, and is now distributed and maintained by Caldera.
A format string vulnerability in the locale subsystem could lead to a user gaining elevated privileges. A local user could potentially supply maliciously crafted message catalogs through the LC_MESSAGES environment variable. This could allow a local user to load arbitrary message catalogs into setuid or setgid programs, and execute arbitrary code with setuid/setgid privileges.
Exploit / POC
Caldera UnixWare Message Catalog Environment Variable Format String Vulnerability
Exploit contributed by jGgM. <[email protected]>:
Exploit contributed by jGgM. <[email protected]>:
Solution / Fix
Caldera UnixWare Message Catalog Environment Variable Format String Vulnerability
Solution:
Vendor fix now available:
Caldera UnixWare 7.1.1
Solution:
Vendor fix now available:
Caldera UnixWare 7.1.1
-
Caldera erg711179.Z
ftp://stage.caldera.com/pub/security/unixware/CSSA-2002-SCO.3/erg71117 9.Z
References
Caldera UnixWare Message Catalog Environment Variable Format String Vulnerability
References:
References: