PT-2005-4352 · Veritas · Veritas Cluster Server

Kevin Finisterre

·

Published

2005-11-16

·

Updated

2017-07-11

·

CVE-2005-3566

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VERITAS Cluster Server for UNIX versions prior to 4.0MP2
Description The issue is related to a buffer overflow in various ha commands, allowing local users to execute arbitrary code via a long VCSI18N LANG environment variable. This affects multiple commands, including haagent, haalert, haattr, hacli, hacli runcmd, haclus, haconf, hadebug, hagrp, hahb, halog, hareg, hares, hastatus, hasys, hatype, hauser, and tststew.
Recommendations For versions prior to 4.0MP2, update to version 4.0MP2 or later to resolve the issue. As a temporary workaround, consider restricting the length of the VCSI18N LANG environment variable to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3566

Affected Products

Veritas Cluster Server