CDE LibDTHelp DTHelpUserSearchPath Local Buffer Overflow Vulnerability
BID:8973
Info
CDE LibDTHelp DTHelpUserSearchPath Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8973 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0834 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 04 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery credited to Kevin Kotas. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 SCO Unixware 7.1.3 SCO Unixware 7.1.1 SCO Open UNIX 8.0 HP HP-UX (VVOS) 11.0 4 HP HP-UX 11.23 HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 Compaq Tru64 5.1 PK6 (BL20) Compaq Tru64 5.1 PK5 (BL19) Compaq Tru64 5.1 PK4 (BL18) Compaq Tru64 5.1 PK3 (BL17) Compaq Tru64 5.1 Compaq Tru64 5.0 f Compaq Tru64 5.0 a PK3 (BL17) Compaq Tru64 5.0 a Compaq Tru64 5.0 PK4 (BL18) Compaq Tru64 5.0 PK4 (BL17) Compaq Tru64 5.0 Compaq Tru64 4.0 g PK4 (BL22) Compaq Tru64 4.0 g PK3 (BL17) Compaq Tru64 4.0 g Compaq Tru64 4.0 f PK8 (BL22) Compaq Tru64 4.0 f PK7 (BL18) Compaq Tru64 4.0 f PK6 (BL17) Compaq Tru64 4.0 f |
| Not Vulnerable: | |
Discussion
CDE LibDTHelp DTHelpUserSearchPath Local Buffer Overflow Vulnerability
A problem has been identified in CDE libDtHelp. Because of this, it may be possible for a local attacker to gain elevated privileges.
A problem has been identified in CDE libDtHelp. Because of this, it may be possible for a local attacker to gain elevated privileges.
Exploit / POC
CDE LibDTHelp DTHelpUserSearchPath Local Buffer Overflow Vulnerability
Raptor has made the following exploits available:
Raptor has made the following exploits available:
Solution / Fix
CDE LibDTHelp DTHelpUserSearchPath Local Buffer Overflow Vulnerability
Solution:
Hewlett-Packard has released an updated advisory (HPSBUX0311-297 Rev. 2) to address this issue. Customers who are potentially affected by this vulnerability are advised to apply the appropriate patch as soon as possible. Further information regarding the application of these patches is available in the referenced advisory. Patches are linked below.
SCO has released advisory CSSA-2003-SCO.31 with fixes to address this issue.
Sun has released Alert ID 57414 with patches to address this issue. A final solution for all affected platforms is pending.
HP has released advisory SSRT3657 to address this issue in Tru64.
SGI has released advisory 20040801-01-P with fixes to address this issue. Please see the referenced advisory for further information.
HP has released a revised advisory (SSRT3657 rev.3) to address this issue. Please see the referenced advisory for more information.
Sun Solaris 7.0
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 7.0_x86
Sun Solaris 8_x86
Sun Solaris 8_sparc
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0 4
HP HP-UX 11.11
HP HP-UX 11.22
HP HP-UX 11.23
Compaq Tru64 5.1 PK4 (BL18)
Compaq Tru64 5.1
Compaq Tru64 5.1 PK3 (BL17)
Compaq Tru64 5.1 PK6 (BL20)
Compaq Tru64 5.1 PK5 (BL19)
SCO Unixware 7.1.1
SCO Unixware 7.1.3
SCO Open UNIX 8.0
Solution:
Hewlett-Packard has released an updated advisory (HPSBUX0311-297 Rev. 2) to address this issue. Customers who are potentially affected by this vulnerability are advised to apply the appropriate patch as soon as possible. Further information regarding the application of these patches is available in the referenced advisory. Patches are linked below.
SCO has released advisory CSSA-2003-SCO.31 with fixes to address this issue.
Sun has released Alert ID 57414 with patches to address this issue. A final solution for all affected platforms is pending.
HP has released advisory SSRT3657 to address this issue in Tru64.
SGI has released advisory 20040801-01-P with fixes to address this issue. Please see the referenced advisory for further information.
HP has released a revised advisory (SSRT3657 rev.3) to address this issue. Please see the referenced advisory for more information.
Sun Solaris 7.0
Sun Solaris 9
Sun Solaris 9_x86
-
Sun T116309-01
http://sunsolve.sun.com
Sun Solaris 7.0_x86
Sun Solaris 8_x86
Sun Solaris 8_sparc
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0 4
-
HP PHSS_30167
http://itrc.hp.com
HP HP-UX 11.11
HP HP-UX 11.22
-
HP PHSS_30012
http://itrc.hp.com
HP HP-UX 11.23
-
HP PHSS_30013
http://itrc.hp.com
Compaq Tru64 5.1 PK4 (BL18)
-
HP T64KIT0020835-V51B20-ES-20031124
Patch requires PK6 (BL20)
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT0020 835-V51B20-ES-20031124
Compaq Tru64 5.1
-
HP T64KIT0020835-V51B20-ES-20031124
Patch requires PK6 (BL20)
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT0020 835-V51B20-ES-20031124
Compaq Tru64 5.1 PK3 (BL17)
-
HP T64KIT0020835-V51B20-ES-20031124
Patch requires PK6 (BL20)
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT0020 835-V51B20-ES-20031124
Compaq Tru64 5.1 PK6 (BL20)
-
HP T64KIT0020835-V51B20-ES-20031124
Patch requires PK6 (BL20)
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT0020 835-V51B20-ES-20031124
Compaq Tru64 5.1 PK5 (BL19)
-
HP T64KIT0020835-V51B20-ES-20031124
Patch requires PK6 (BL20)
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT0020 835-V51B20-ES-20031124
SCO Unixware 7.1.1
-
SCO erg712445.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.31
SCO Unixware 7.1.3
-
SCO erg712445.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.31
SCO Open UNIX 8.0
-
SCO erg712445.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.31
References
CDE LibDTHelp DTHelpUserSearchPath Local Buffer Overflow Vulnerability
References:
References:
- Sun Alert ID: 57414 (Sun Microsystems)