SCO UnixWare xlock(1) (long username) Buffer Overflow Vulnerability
BID:825
Info
SCO UnixWare xlock(1) (long username) Buffer Overflow Vulnerability
| Bugtraq ID: | 825 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 25 1999 12:00AM |
| Updated: | Nov 25 1999 12:00AM |
| Credit: | The exploit posted to the Bug mailing list for this vulnerability lists AK (two@two) as the author and discoverer of this bug. It was posted to the Bug mailing list on Nov 25 1999 . |
| Vulnerable: |
SCO Unixware 7.0 |
| Not Vulnerable: | |
Discussion
SCO UnixWare xlock(1) (long username) Buffer Overflow Vulnerability
Certain versions of Unixware ship with a version of xlock which is vulnerable to a buffer overflow attack. The xlock(1) program locks the local X display until a username and password are entered. In this instance a user can provide an overly long username and overflow a buffer in xlock(1). Given that xlock(1) runs SUID root this will result in a root compromise.
Certain versions of Unixware ship with a version of xlock which is vulnerable to a buffer overflow attack. The xlock(1) program locks the local X display until a username and password are entered. In this instance a user can provide an overly long username and overflow a buffer in xlock(1). Given that xlock(1) runs SUID root this will result in a root compromise.
References
SCO UnixWare xlock(1) (long username) Buffer Overflow Vulnerability
References:
References: