PT-2002-2723 · Compaq · Compaq Tru64

Published

2002-12-31

·

Updated

2011-03-08

·

CVE-2002-2002

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Compaq Tru64 versions 4.0F, 5.0, 5.1, and 5.1A
Description The issue is related to a buffer overflow in the libc component. This occurs when an attacker provides long values for the LANG and LOCPATH environment variables, potentially allowing the execution of arbitrary code.
Recommendations For Compaq Tru64 versions 4.0F, 5.0, 5.1, and 5.1A, consider restricting the length of the LANG and LOCPATH environment variables to prevent buffer overflow exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2002

Affected Products

Compaq Tru64