CDE DTSession Unspecified Privilege Escalation Vulnerability
BID:7720
Info
CDE DTSession Unspecified Privilege Escalation Vulnerability
| Bugtraq ID: | 7720 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 28 2003 12:00AM |
| Updated: | May 28 2003 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.20 Series 800 HP HP-UX 10.20 Series 700 HP HP-UX 10.20 Compaq Tru64 5.1 b PK1 (BL1) Compaq Tru64 5.1 b Compaq Tru64 5.1 a PK4 (BL21) Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 a PK2 (BL2) Compaq Tru64 5.1 a PK1 (BL1) Compaq Tru64 5.1 a Compaq Tru64 5.1 PK6 (BL20) Compaq Tru64 5.1 PK5 (BL19) Compaq Tru64 5.1 PK4 (BL18) Compaq Tru64 5.1 PK3 (BL17) Compaq Tru64 5.1 Compaq Tru64 4.0 g PK3 (BL17) Compaq Tru64 4.0 g Compaq Tru64 4.0 f PK7 (BL18) Compaq Tru64 4.0 f PK6 (BL17) Compaq Tru64 4.0 f |
| Not Vulnerable: | |
Discussion
CDE DTSession Unspecified Privilege Escalation Vulnerability
A vulnerability the CDE DTsession utility has been identified that may result in privilege escalation. It is believed that this is due to a locally exploitable buffer overrun, which could permit execution of malicious instructions with elevated privileges.
It is not known if this issue affects CDE on other platforms.
A vulnerability the CDE DTsession utility has been identified that may result in privilege escalation. It is believed that this is due to a locally exploitable buffer overrun, which could permit execution of malicious instructions with elevated privileges.
It is not known if this issue affects CDE on other platforms.
Exploit / POC
CDE DTSession Unspecified Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CDE DTSession Unspecified Privilege Escalation Vulnerability
Solution:
HP has released a security bulletin (SRB0081W_0) and fixes to address this issue.
HP has released fixes to address this issue in Tru64.
HP has also released a security bulletin (HPSBUX0306-263 rev.2) which contains fixes to address this issue in affected HP-UX releases. Users are advised to upgrade as soon as possible.
HP HP-UX 10.20 Series 800
HP HP-UX 10.20 Series 700
HP HP-UX 10.20
HP HP-UX 11.0
HP HP-UX 11.0 4
HP HP-UX 11.11
HP HP-UX 11.22
Compaq Tru64 4.0 f
Compaq Tru64 4.0 f PK6 (BL17)
Compaq Tru64 4.0 g PK3 (BL17)
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f PK7 (BL18)
Compaq Tru64 5.1 a PK1 (BL1)
Compaq Tru64 5.1 a PK2 (BL2)
Compaq Tru64 5.1 a PK4 (BL21)
Compaq Tru64 5.1 a PK3 (BL3)
Compaq Tru64 5.1 PK4 (BL18)
Compaq Tru64 5.1 b PK1 (BL1)
Compaq Tru64 5.1 a
Compaq Tru64 5.1 b
Compaq Tru64 5.1
Compaq Tru64 5.1 PK3 (BL17)
Compaq Tru64 5.1 PK6 (BL20)
Compaq Tru64 5.1 PK5 (BL19)
Solution:
HP has released a security bulletin (SRB0081W_0) and fixes to address this issue.
HP has released fixes to address this issue in Tru64.
HP has also released a security bulletin (HPSBUX0306-263 rev.2) which contains fixes to address this issue in affected HP-UX releases. Users are advised to upgrade as soon as possible.
HP HP-UX 10.20 Series 800
-
HP PHSS_29201
http://itrc.hp.com -
HP PHSS_29202
http://itrc.hp.com
HP HP-UX 10.20 Series 700
-
HP PHSS_29201
http://itrc.hp.com -
HP PHSS_29202
http://itrc.hp.com
HP HP-UX 10.20
-
HP PHSS_29201
http://itrc.hp.com -
HP PHSS_29202
http://itrc.hp.com
HP HP-UX 11.0
-
HP PHSS_28675
ftp://ftp.itrc.hp.com/hp-ux_patches/s700_800/11.X/PHSS_28675 -
HP PHSS_28678
ftp://ftp.itrc.hp.com/hp-ux_patches/s700_800/11.X/PHSS_28678
HP HP-UX 11.0 4
HP HP-UX 11.11
-
HP PHSS_28676
ftp://ftp.itrc.hp.com/hp-ux_patches/s700_800/11.X/PHSS_28676 -
HP PHSS_28677
ftp://ftp.itrc.hp.com/hp-ux_patches/s700_800/11.X/PHSS_28677 -
HP PHSS_28679
ftp://ftp.itrc.hp.com/hp-ux_patches/s700_800/11.X/PHSS_28679
HP HP-UX 11.22
-
HP PHSS_28682
ftp://ftp.itrc.hp.com/hp-ux_patches/s700_800/11.X/PHSS_28682 -
HP PHSS_28683
ftp://ftp.itrc.hp.com/hp-ux_patches/s700_800/11.X/PHSS_28683
Compaq Tru64 4.0 f
-
HP DUV40FB18-C0093801-18528-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v4.0f
Compaq Tru64 4.0 f PK6 (BL17)
-
HP DUV40FB18-C0093801-18528-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v4.0f
Compaq Tru64 4.0 g PK3 (BL17)
-
HP T64V40GB17-C0029600-18524-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v4.0g
Compaq Tru64 4.0 g
-
HP T64V40GB17-C0029600-18524-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v4.0g
Compaq Tru64 4.0 f PK7 (BL18)
-
HP DUV40FB18-C0093801-18528-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v4.0f
Compaq Tru64 5.1 a PK1 (BL1)
-
HP T64V51AB21-C0114000-18502-ES-20030505
http://ftp.support.compaq.com/patches/public/unix/v5.1a
Compaq Tru64 5.1 a PK2 (BL2)
-
HP T64V51AB21-C0114000-18502-ES-20030505
http://ftp.support.compaq.com/patches/public/unix/v5.1a
Compaq Tru64 5.1 a PK4 (BL21)
-
HP T64V51AB21-C0114000-18502-ES-20030505
http://ftp.support.compaq.com/patches/public/unix/v5.1a
Compaq Tru64 5.1 a PK3 (BL3)
-
HP T64V51AB21-C0114000-18502-ES-20030505
http://ftp.support.compaq.com/patches/public/unix/v5.1a
Compaq Tru64 5.1 PK4 (BL18)
-
HP T64V51B20-C0177500-18521-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v5.1
Compaq Tru64 5.1 b PK1 (BL1)
-
HP T64V51BB1-C0009800-18447-ES-20030430
http://ftp.support.compaq.com/patches/public/unix/v5.1b
Compaq Tru64 5.1 a
-
HP T64V51AB21-C0114000-18502-ES-20030505
http://ftp.support.compaq.com/patches/public/unix/v5.1a
Compaq Tru64 5.1 b
-
HP T64V51BB1-C0009800-18447-ES-20030430
http://ftp.support.compaq.com/patches/public/unix/v5.1b
Compaq Tru64 5.1
-
HP T64V51B20-C0177500-18521-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v5.1
Compaq Tru64 5.1 PK3 (BL17)
-
HP T64V51B20-C0177500-18521-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v5.1
Compaq Tru64 5.1 PK6 (BL20)
-
HP T64V51B20-C0177500-18521-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v5.1
Compaq Tru64 5.1 PK5 (BL19)
-
HP T64V51B20-C0177500-18521-ES-20030506
http://ftp.support.compaq.com/patches/public/unix/v5.1
References
CDE DTSession Unspecified Privilege Escalation Vulnerability
References:
References: