PT-2005-4352 · Veritas · Veritas Cluster Server
Kevin Finisterre
·
Published
2005-11-16
·
Updated
2017-07-11
·
CVE-2005-3566
CVSS v2.0
4.3
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VERITAS Cluster Server for UNIX versions prior to 4.0MP2
Description
The issue is related to a buffer overflow in various ha commands, allowing local users to execute arbitrary code via a long
VCSI18N LANG environment variable. This affects multiple commands, including haagent, haalert, haattr, hacli, hacli runcmd, haclus, haconf, hadebug, hagrp, hahb, halog, hareg, hares, hastatus, hasys, hatype, hauser, and tststew.Recommendations
For versions prior to 4.0MP2, update to version 4.0MP2 or later to resolve the issue. As a temporary workaround, consider restricting the length of the
VCSI18N LANG environment variable to prevent exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veritas Cluster Server