PT-2002-1316 · Unixware · Unixware

Publicado

2002-05-29

·

Atualizado

2008-09-11

·

CVE-2002-0246

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions UnixWare version 7.1.1
Description A format string issue exists in the message catalog library functions of UnixWare, allowing local users to elevate privileges. This is achieved by modifying the LC MESSAGE environment variable to access other message catalogs that contain format strings from setuid programs, such as vxprint.
Recommendations For UnixWare version 7.1.1, as a temporary workaround, consider restricting access to setuid programs like vxprint until a patch is available. Additionally, avoid modifying the LC MESSAGE environment variable to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0246

Produtos afetados

Unixware