HP-UX UUSUB System Hostname Buffer Overflow Vulnerability
BID:7798
Info
HP-UX UUSUB System Hostname Buffer Overflow Vulnerability
| Bugtraq ID: | 7798 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Jun 03 2003 12:00AM |
| Updated: | Jun 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to LSD Research Group (http://lsd-pl.net). |
| Vulnerable: |
HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.20 |
| Not Vulnerable: | |
Discussion
HP-UX UUSUB System Hostname Buffer Overflow Vulnerability
A vulnerability has been discovered in the HP-UX implementation of uusub. The problem is due to insufficient bounds checking when handling user-supplied command-line arguments. As a result, it is possible for an attacker to exploit this issue to corrupt uusub process memory.
Successful exploitation of this issue would allow an attacker to execute arbitrary code, with the privileges of uusub.
A vulnerability has been discovered in the HP-UX implementation of uusub. The problem is due to insufficient bounds checking when handling user-supplied command-line arguments. As a result, it is possible for an attacker to exploit this issue to corrupt uusub process memory.
Successful exploitation of this issue would allow an attacker to execute arbitrary code, with the privileges of uusub.
Exploit / POC
HP-UX UUSUB System Hostname Buffer Overflow Vulnerability
Last Stage of Delirium has announced that a proof of concept exploit has been developed, however it has not yet been made publicily available.
Last Stage of Delirium has announced that a proof of concept exploit has been developed, however it has not yet been made publicily available.
Solution / Fix
HP-UX UUSUB System Hostname Buffer Overflow Vulnerability
Solution:
The vendor has released a patch for HP-UX 11.00 and 11.11 dealing with this issue. The vendor advises that the preliminary patches MUST be removed before the new patches are applied. A failure to remove the preliminary patches could cause corruption of the affected system or facilitate re-introduction of the issue. The files to be removed are:
PHCO_29106.depot for HP-UX 11.00
UNOF_29107.depot for HP-UX 11.11
HP HP-UX 10.20
HP HP-UX 11.0
HP HP-UX 11.11
Solution:
The vendor has released a patch for HP-UX 11.00 and 11.11 dealing with this issue. The vendor advises that the preliminary patches MUST be removed before the new patches are applied. A failure to remove the preliminary patches could cause corruption of the affected system or facilitate re-introduction of the issue. The files to be removed are:
PHCO_29106.depot for HP-UX 11.00
UNOF_29107.depot for HP-UX 11.11
HP HP-UX 10.20
-
HP PHCO_29105.depot
ftp://hprc.external.hp.com/PHCO_29105.depot -
HP PHCO_29106.depot
ftp://hprc.external.hp.com/PHCO_29106.depot
HP HP-UX 11.0
-
HP PHCO_29381
http://itrc.hp.com -
HP PHCO_29106.depot
ftp://hprc.external.hp.com/PHCO_29106.depot
HP HP-UX 11.11
-
HP PHCO_29382
http://itrc.hp.com -
HP PHCO_29107.depot
ftp://hprc.external.hp.com/PHCO_29107.depot
References
HP-UX UUSUB System Hostname Buffer Overflow Vulnerability
References:
References:
- [LSD] HP-UX security vulnerabilities (Last Stage of Delirium
)