SCO UnixWare Xsco Buffer Overflow Vulnerability
BID:824
Info
SCO UnixWare Xsco Buffer Overflow Vulnerability
| Bugtraq ID: | 824 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 25 1999 12:00AM |
| Updated: | Nov 25 1999 12:00AM |
| Credit: | The exploit posted to the Bugtraq mailing list for this vulnerability lists K2 ([email protected]) as the author and discoverer of this bug. It was posted to the Bugtraq mailing list on Nov 25 1999 . |
| Vulnerable: |
SCO Unixware 7.1 SCO Unixware 7.0.1 SCO Unixware 7.0 |
| Not Vulnerable: | |
Discussion
SCO UnixWare Xsco Buffer Overflow Vulnerability
Under certain versions of Unixware, the SUID program Xsco is vulnerable to a buffer overflow attack. The problem lies in that Xsco does not sanity check user supplied data.
Under certain versions of Unixware, the SUID program Xsco is vulnerable to a buffer overflow attack. The problem lies in that Xsco does not sanity check user supplied data.
Exploit / POC
SCO UnixWare Xsco Buffer Overflow Vulnerability
exploit available
exploit available
Solution / Fix
SCO UnixWare Xsco Buffer Overflow Vulnerability
Solution:
SCO has released SSE041 to address this problem. Details are available from:
ftp://ftp.sco.com/SSE/sse041.ltr
Solution:
SCO has released SSE041 to address this problem. Details are available from:
ftp://ftp.sco.com/SSE/sse041.ltr
References
SCO UnixWare Xsco Buffer Overflow Vulnerability
References:
References: