SCO OpenServer X Library Buffer Overflow Vulnerability
BID:638
Info
SCO OpenServer X Library Buffer Overflow Vulnerability
| Bugtraq ID: | 638 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 1999 12:00AM |
| Updated: | Sep 09 1999 12:00AM |
| Credit: | First posted to BugTraq by Brock Tellier <[email protected]> on September 9, 1999. |
| Vulnerable: |
SCO Open Server 5.0.5 |
| Not Vulnerable: | |
Discussion
SCO OpenServer X Library Buffer Overflow Vulnerability
A buffer overflow vulnerability in the shared X library may allows local users to obtain higher privileges. Any setuid applications linked against the library are possibly vulnerable. The vulnerability is in the handling of the '-bg' command line parameter.
Setuid root applications known to be vulnerable inclue xload, xmcd, xterm, and scoterm.
Setuid bin applications known to be vulnerable include scosession.
A buffer overflow vulnerability in the shared X library may allows local users to obtain higher privileges. Any setuid applications linked against the library are possibly vulnerable. The vulnerability is in the handling of the '-bg' command line parameter.
Setuid root applications known to be vulnerable inclue xload, xmcd, xterm, and scoterm.
Setuid bin applications known to be vulnerable include scosession.
Solution / Fix
SCO OpenServer X Library Buffer Overflow Vulnerability
Solution:
A temporary solution is removing the setuid bit (limiting the functionality of the application) on all affected applications.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
A temporary solution is removing the setuid bit (limiting the functionality of the application) on all affected applications.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
SCO OpenServer X Library Buffer Overflow Vulnerability
References:
References:
- SCO Homepage (Santa Cruz Operaton)