SCO UnixWare 'xauto' Buffer Overflow Vulnerability
BID:848
Info
SCO UnixWare 'xauto' Buffer Overflow Vulnerability
| Bugtraq ID: | 848 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 03 1999 12:00AM |
| Updated: | Dec 03 1999 12:00AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list by Brock Tellier on Dec 3, 1999. |
| Vulnerable: |
SCO Unixware 7.1.1 SCO Unixware 7.1 SCO Unixware 7.0.1 SCO Unixware 7.0 |
| Not Vulnerable: | |
Discussion
SCO UnixWare 'xauto' Buffer Overflow Vulnerability
Certain versions of SCO's UnixWare ship with a version of /usr/X/bin/xauto which is vulnerable to a buffer overflow attack which may result in an attacker gaining root privileges.
This is exploitable to gain root privileges even though /usr/X/bin/xauto is not setuid root. This is due to a system design issue with SCO Unixware which is discussed in an attached message in the 'Credit' section titled "UnixWare 7 uidadmin exploit + discussion".
Certain versions of SCO's UnixWare ship with a version of /usr/X/bin/xauto which is vulnerable to a buffer overflow attack which may result in an attacker gaining root privileges.
This is exploitable to gain root privileges even though /usr/X/bin/xauto is not setuid root. This is due to a system design issue with SCO Unixware which is discussed in an attached message in the 'Credit' section titled "UnixWare 7 uidadmin exploit + discussion".
Exploit / POC
Solution / Fix
References
SCO UnixWare 'xauto' Buffer Overflow Vulnerability
References:
References: