HP-UX缓冲区溢出漏洞

HP-UX缓冲区溢出漏洞

漏洞ID 1107506 漏洞类型 缓冲区溢出
发布时间 2003-10-08 更新时间 2003-11-17
图片[1]-HP-UX缓冲区溢出漏洞-安全小百科CVE编号 CVE-2003-0840
图片[2]-HP-UX缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200311-081
漏洞平台 HP-UX CVSS评分 7.2
|漏洞来源
https://www.exploit-db.com/exploits/23236
https://www.securityfocus.com/bid/82742
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200311-081
|漏洞详情
HP-UX11.00的dtprintinfo以及可能其他的操作系统存在缓冲区溢出漏洞。本地用户借助超长DISPLAY环境变量提升根特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/8795/info

It has been reported that dtprintinfo, installed setuid root by default, is susceptible to a locally exploitable buffer overflow vulnerability. The condition is triggered when the value of the DISPLAY environment variable is set to a string exceeding 9777 bytes in length. The vulnerability may allow for local attackers to gain root privileges on the affected host. 

export DISPLAY="`perl -e 'printf "A" x 9777'`"
|受影响的产品
HP HP-UX 11.0
|参考资料

来源:BUGTRAQ
名称:20031008HPUXdtprintinfobufferoverflowvulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=106563181313571&w;=2

相关推荐: HP-UX movemail权限许可漏洞

HP-UX movemail权限许可漏洞 漏洞ID 1207577 漏洞类型 未知 发布时间 1997-01-06 更新时间 1997-01-06 CVE编号 CVE-1999-1249 CNNVD-ID CNNVD-199701-044 漏洞平台 N/A C…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享