search menu icon-carat-right cmu-wordmark

CERT Coordination Center

SCO UnixWare uuxqt contains buffer overflow via long string of characters sent as command line argument

Vulnerability Note VU#206019

Original Release Date: 2001-07-27 | Last Revised: 2001-07-27

Overview

A buffer overflow in uuxqt, part of the UUCP package on SCO systems, can allow an intruder to gain elevated privileges.

Description

SCO UnixWare 7 ships with a utility package called UUCP. The UUCP package allows for the copying of files between different UNIX systems and the sending of commands for execution on a remote system. There is a buffer overflow in the uuxqt application, which is part of the package. A malicious user can use these vulnerabilities to gain elevated privileges.

Impact

A malicious local user can gain elevated privileges.

Solution

Caldera has released binaries that fix the problem. They are located at ftp://ftp.sco.com/pub/security/unixware/sr847405/.

Vendor Information

206019
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported in a Caldera-SCO security advisory.

This document was written by Jason Rafail.

Other Information

CVE IDs: None
Severity Metric: 0.18
Date Public: 2001-06-27
Date First Published: 2001-07-27
Date Last Updated: 2001-07-27 19:17 UTC
Document Revision: 14

Sponsored by CISA.