PT-2006-1255 · Cray · Cray Unicos

Published

2006-01-11

·

Updated

2017-07-20

·

CVE-2006-0177

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cray UNICOS version 9.0.2.2
Description The issue is related to multiple buffer overflows that could allow local users to gain privileges. This can be achieved by either invoking /usr/bin/script with a long command line argument or setting the -c option of /etc/nu to the name of a file containing a long line.
Recommendations For Cray UNICOS version 9.0.2.2, consider restricting access to the /usr/bin/script and /etc/nu to minimize the risk of exploitation. As a temporary workaround, avoid using long command line arguments with /usr/bin/script and refrain from setting the -c option of /etc/nu to files with long lines until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0177

Affected Products

Cray Unicos