PT-2005-4352 · Veritas · Veritas Cluster Server
Kevin Finisterre
·
Publicado
2005-11-16
·
Atualizado
2017-07-11
·
CVE-2005-3566
CVSS v2.0
4.3
Média
| Vetor | AV:L/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VERITAS Cluster Server for UNIX versions prior to 4.0MP2
Description
The issue is related to a buffer overflow in various ha commands, allowing local users to execute arbitrary code via a long
VCSI18N LANG environment variable. This affects multiple commands, including haagent, haalert, haattr, hacli, hacli runcmd, haclus, haconf, hadebug, hagrp, hahb, halog, hareg, hares, hastatus, hasys, hatype, hauser, and tststew.Recommendations
For versions prior to 4.0MP2, update to version 4.0MP2 or later to resolve the issue. As a temporary workaround, consider restricting the length of the
VCSI18N LANG environment variable to prevent exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Veritas Cluster Server