PT-2006-1255 · Cray · Cray Unicos
Published
2006-01-11
·
Updated
2017-07-20
·
CVE-2006-0177
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cray UNICOS version 9.0.2.2
Description
The issue is related to multiple buffer overflows that could allow local users to gain privileges. This can be achieved by either invoking
/usr/bin/script with a long command line argument or setting the -c option of /etc/nu to the name of a file containing a long line.Recommendations
For Cray UNICOS version 9.0.2.2, consider restricting access to the
/usr/bin/script and /etc/nu to minimize the risk of exploitation. As a temporary workaround, avoid using long command line arguments with /usr/bin/script and refrain from setting the -c option of /etc/nu to files with long lines until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cray Unicos