HP-UX RExec Remote Username Flag Local Buffer Overrun Vulnerability
BID:7459
Info
HP-UX RExec Remote Username Flag Local Buffer Overrun Vulnerability
| Bugtraq ID: | 7459 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 29 2003 12:00AM |
| Updated: | Apr 29 2003 12:00AM |
| Credit: | Discovery credited to "Davide Del Vecchio" <[email protected]>. |
| Vulnerable: |
HP HP-UX 11.22 HP HP-UX 11.20 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.34 HP HP-UX 10.30 HP HP-UX 10.26 HP HP-UX 10.24 HP HP-UX 10.20 HP HP-UX 10.16 HP HP-UX 10.10 |
| Not Vulnerable: | |
Discussion
HP-UX RExec Remote Username Flag Local Buffer Overrun Vulnerability
It has been reported that a problem in the rexec program included with some versions of HP-UX may be vulnerable to a boundary condition error. It may be possible for a local user to exploit this vulnerability to gain elevated privileges on the system.
It has been reported that a problem in the rexec program included with some versions of HP-UX may be vulnerable to a boundary condition error. It may be possible for a local user to exploit this vulnerability to gain elevated privileges on the system.
Exploit / POC
HP-UX RExec Remote Username Flag Local Buffer Overrun Vulnerability
A proof of concept has been made available by "Davide Del Vecchio" <[email protected]>:
rexec 127.0.0.1 -l `perl -e 'printf "A" x 9777'` -n something
-----
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
A proof of concept has been made available by "Davide Del Vecchio" <[email protected]>:
rexec 127.0.0.1 -l `perl -e 'printf "A" x 9777'` -n something
-----
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP-UX RExec Remote Username Flag Local Buffer Overrun Vulnerability
Solution:
HP has released fixes for HP-UX 10.20, 11.00, 11.04. Users of HP-UX 10.10 systems, as a temporary measure, are advised to download and install libc.1.10.20 on affected systems. This file can be found at the following location.
ftp://rexec:[email protected]/
ftp://rexec:[email protected]/
Further information, and instructions, are available in the referenced advisory HPSBUX0304-257.
HP HP-UX 11.0
Solution:
HP has released fixes for HP-UX 10.20, 11.00, 11.04. Users of HP-UX 10.10 systems, as a temporary measure, are advised to download and install libc.1.10.20 on affected systems. This file can be found at the following location.
ftp://rexec:[email protected]/
ftp://rexec:[email protected]/
Further information, and instructions, are available in the referenced advisory HPSBUX0304-257.
HP HP-UX 11.0
-
HP PHCO_24723
http://itrc.hp.com/
References
HP-UX RExec Remote Username Flag Local Buffer Overrun Vulnerability
References:
References:
- HPUX rexec buffer overflow vulnerability ("Davide Del Vecchio"
)