search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Taylor UUCP Package fails to properly filter command line arguments

Vulnerability Note VU#798263

Original Release Date: 2001-09-25 | Last Revised: 2002-02-08

Overview

Several Linux/Unix systems ship with a utility package called Taylor UUCP. A component of the UUCP package, uuxqt, fails to properly filter arguments from the commands sent to it. This can allow an intruder to gain elevated privileges and execute commands with the privileges of uucp, usually root.

Description

A component of the UUCP package, uuxqt, is a daemon that executes commands requested by uux either from the local system or from remote systems. Before executing the command, uuxqt is supposed to filter dangerous command arguments. It fails to properly filter command line arguments that are specified in their long format. This can allow an intruder to gain elevated privileges and execute commands.

Impact

An intruder can gain elevated privileges and execute commands.

Solution

Apply the patches and upgrades provided by your vendor.

Vendor Information

798263
 

View all 11 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was discovered by zen-parse.

This document was written by Jason Rafail.

Other Information

CVE IDs: CVE-2001-0873
Severity Metric: 21.38
Date Public: 2001-09-08
Date First Published: 2001-09-25
Date Last Updated: 2002-02-08 16:09 UTC
Document Revision: 10

Sponsored by CISA.