Caldera X11 Library -xrm Buffer Overflow Vulnerability
BID:4502
Info
Caldera X11 Library -xrm Buffer Overflow Vulnerability
| Bugtraq ID: | 4502 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0517 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 11 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Vulnerability announced in a Caldera Security Advisory. |
| Vulnerable: |
Caldera UnixWare 7.1.1 Caldera OpenUnix 8.0 |
| Not Vulnerable: | |
Discussion
Caldera X11 Library -xrm Buffer Overflow Vulnerability
OpenUnix is a derivative of UnixWare, both Unix Operating System derivatives distributed and maintained by Caldera.
Under some circumstances, it is possible to take advantage of a buffer overflow that may yield elevated privileges. Programs that have been linked against the vulnerable X11 library do not perform proper bounds checking when the -xrm flag is used. This could allow the overwriting of stack variables, including the return address, and code execution.
OpenUnix is a derivative of UnixWare, both Unix Operating System derivatives distributed and maintained by Caldera.
Under some circumstances, it is possible to take advantage of a buffer overflow that may yield elevated privileges. Programs that have been linked against the vulnerable X11 library do not perform proper bounds checking when the -xrm flag is used. This could allow the overwriting of stack variables, including the return address, and code execution.
Exploit / POC
Caldera X11 Library -xrm Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Caldera X11 Library -xrm Buffer Overflow Vulnerability
Solution:
Fixes available:
Caldera UnixWare 7.1.1
Caldera OpenUnix 8.0
Solution:
Fixes available:
Caldera UnixWare 7.1.1
-
Caldera basex.711b.pkg
ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.15
Caldera OpenUnix 8.0
-
Caldera basex.711b.pkg
ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.15
References
Caldera X11 Library -xrm Buffer Overflow Vulnerability
References:
References: