HP-UX UUCP Unspecified Buffer Overflow Vulnerability
BID:7796
Info
HP-UX UUCP Unspecified Buffer Overflow Vulnerability
| Bugtraq ID: | 7796 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Jun 03 2003 12:00AM |
| Updated: | Jun 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to LSD Research Group (http://lsd-pl.net). |
| Vulnerable: |
HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.20 |
| Not Vulnerable: | |
Discussion
HP-UX UUCP Unspecified Buffer Overflow Vulnerability
A vulnerability has been discovered in the HP-UX implementation of UUCP. The problem is likely due to insufficient bounds checking of user-supplied data.
An attacker may exploit this issue to overwrite sensitive locations in memory, it may be possible for an attacker to execute arbitrary code.
As UUCP is installed setuid root this would result in the execution of attacker-supplied commands with the privileges of the superuser.
A vulnerability has been discovered in the HP-UX implementation of UUCP. The problem is likely due to insufficient bounds checking of user-supplied data.
An attacker may exploit this issue to overwrite sensitive locations in memory, it may be possible for an attacker to execute arbitrary code.
As UUCP is installed setuid root this would result in the execution of attacker-supplied commands with the privileges of the superuser.
Exploit / POC
HP-UX UUCP Unspecified Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP-UX UUCP Unspecified Buffer Overflow Vulnerability
Solution:
The vendor has released a patch for HP-UX 11.00 and 11.11 dealing with this issue. The vendor advises that the preliminary patches MUST be removed before the new patches are applied. A failure to remove the preliminary patches could cause corruption of the affected system or facilitate re-introduction of the issue. The files to be removed are:
PHCO_29106.depot for HP-UX 11.00
UNOF_29107.depot for HP-UX 11.11
HP HP-UX 10.20
HP HP-UX 11.0
HP HP-UX 11.11
Solution:
The vendor has released a patch for HP-UX 11.00 and 11.11 dealing with this issue. The vendor advises that the preliminary patches MUST be removed before the new patches are applied. A failure to remove the preliminary patches could cause corruption of the affected system or facilitate re-introduction of the issue. The files to be removed are:
PHCO_29106.depot for HP-UX 11.00
UNOF_29107.depot for HP-UX 11.11
HP HP-UX 10.20
-
HP PHCO_29105.depot
ftp://hprc.external.hp.com/PHCO_29105.depot -
HP PHCO_29106.depot
ftp://hprc.external.hp.com/PHCO_29106.depot
HP HP-UX 11.0
-
HP PHCO_29381
http://itrc.hp.com -
HP PHCO_29106.depot
ftp://hprc.external.hp.com/PHCO_29106.depot
HP HP-UX 11.11
-
HP PHCO_29382
http://itrc.hp.com -
HP PHCO_29107.depot
ftp://hprc.external.hp.com/PHCO_29107.depot
References
HP-UX UUCP Unspecified Buffer Overflow Vulnerability
References:
References:
- [LSD] HP-UX security vulnerabilities (Last Stage of Delirium
)