SCO OpenServer xlock Buffer (-bg) Overflow Vulnerability
BID:642
Info
SCO OpenServer xlock Buffer (-bg) Overflow Vulnerability
| Bugtraq ID: | 642 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 1999 12:00AM |
| Updated: | Sep 09 1999 12:00AM |
| Credit: | First posted to BugTraq by Brock Tellier <[email protected]> on September 9, 1999. |
| Vulnerable: |
SCO Open Server 5.0.5 |
| Not Vulnerable: | |
Discussion
SCO OpenServer xlock Buffer (-bg) Overflow Vulnerability
SCO xlock is installed suid auth, which means read and write permissions on /etc/shadow. SCO xlock is vulnerable to a buffer overflow attack allowing arbitrary code to be executed with auth privileges. If exploited, a local root compromise is possible.
SCO xlock is installed suid auth, which means read and write permissions on /etc/shadow. SCO xlock is vulnerable to a buffer overflow attack allowing arbitrary code to be executed with auth privileges. If exploited, a local root compromise is possible.
Exploit / POC
SCO OpenServer xlock Buffer (-bg) Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].