PT-2001-2304 · Unixware · Unixware
Published
2001-06-27
·
Updated
2008-09-05
·
CVE-2001-1164
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UnixWare 7
Description
A buffer overflow issue exists in the uucp utilities, allowing local users to execute arbitrary code by providing long command line arguments to various utilities, including
uucp, uux, bnuconvert, uucico, uuxcmd, and uuxqt.Recommendations
For UnixWare 7, consider restricting access to the uucp utilities until a patch is available.
As a temporary workaround, consider disabling the execution of the
uucp, uux, bnuconvert, uucico, uuxcmd, and uuxqt utilities to prevent potential exploitation.
Avoid using long command line arguments with these utilities until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unixware