PT-2009-2028 · Sco · Unixware+1
Qaaz
·
Published
2009-03-30
·
Updated
2017-09-29
·
CVE-2008-6558
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ReliantHA version 1.1.4 in SCO UnixWare 7.1.4
Description
The issue allows local users to gain root privileges by modifying the
RELIANT PATH environment variable to point to a malicious bin/hvenv program. This is due to an untrusted search path vulnerability in hvdisp and rcvm components.Recommendations
For ReliantHA version 1.1.4 in SCO UnixWare 7.1.4, consider restricting access to the
RELIANT PATH environment variable to prevent modification by local users. Additionally, monitor and restrict execution of the bin/hvenv program to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Reliantha
Unixware