PT-2001-2663 · Novell+1 · Unixware+1
Published
2001-12-31
·
Updated
2008-09-05
·
CVE-2001-1579
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
UnixWare version 7
OpenUnix version 8.0.0
Description
The issue is related to the timed program (in.timed) that does not properly terminate certain strings with a null. This allows remote attackers to cause a denial of service.
Recommendations
For UnixWare version 7, ensure proper string termination in the timed program to prevent denial of service attacks.
For OpenUnix version 8.0.0, modify the timed program to correctly null-terminate strings and prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Unix
Unixware