Description
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
Affected products
- caldera / openunix8.0 – 8.0
- caldera / unixware7.1_.0 – 7.1_.0
- caldera / unixware7.1.1 – 7.1.1
- caldera / unixware7 – 7
- compaq / tru645.1 – 5.1
- compaq / tru644.0f – 4.0f
- compaq / tru644.0g – 4.0g
- compaq / tru645.0a – 5.0a
- compaq / tru645.1a – 5.1a
- HP / hp-ux10.24 – 10.24
- HP / hp-ux10.10 – 10.10
- HP / hp-ux10.20 – 10.20
- HP / hp-ux11.00 – 11.00
- HP / hp-ux11.11 – 11.11
- ibm / aix4.3.3 – 4.3.3
- ibm / aix5.1 – 5.1
- sgi / irix6.5.7 – 6.5.7
- sgi / irix6.5.8 – 6.5.8
- sgi / irix6.5.9 – 6.5.9
- sgi / irix6.5.10 – 6.5.10
- sgi / irix6.5.11 – 6.5.11
- sgi / irix6.5.12 – 6.5.12
- sgi / irix6.5.13 – 6.5.13
- sgi / irix6.5.14 – 6.5.14
- sgi / irix6.5.15 – 6.5.15
- sgi / irix6.5.16 – 6.5.16
- sgi / irix5.2 – 5.2
- sgi / irix5.3 – 5.3
- sgi / irix6.0 – 6.0
- sgi / irix6.0.1 – 6.0.1
- sgi / irix6.1 – 6.1
- sgi / irix6.2 – 6.2
- sgi / irix6.3 – 6.3
- sgi / irix6.4 – 6.4
- sgi / irix6.5 – 6.5
- sgi / irix6.5.1 – 6.5.1
- sgi / irix6.5.2 – 6.5.2
- sgi / irix6.5.3 – 6.5.3
- sgi / irix6.5.4 – 6.5.4
- sgi / irix6.5.5 – 6.5.5
- sgi / irix6.5.6 – 6.5.6
- sun / solaris2.6 – 2.6
- sun / sunos5.5.1 – 5.5.1
- sun / sunos5.7 – 5.7
- sun / sunos5.8 – 5.8
- xi_graphics / dextop2.1 – 2.1
References
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20021102-02-P
- MISCftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.28/CSSA-2002-SCO.28.txt
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2002-20.html
- MISChttp://www.kb.cert.org/vuls/id/975403
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A91
- MAILING_LISThttp://marc.info/?l=bugtraq&m=102635906423617&w=2
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1099