Description
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
Affected products
- caldera / openunix8.0 – 8.0
- caldera / unixware7.1.1 – 7.1.1
- caldera / unixware7.1.0 – 7.1.0
- caldera / unixware7.0 – 7.0
- compaq / tru645.1 – 5.1
- compaq / tru644.0f – 4.0f
- compaq / tru644.0g – 4.0g
- compaq / tru645.0a – 5.0a
- compaq / tru645.1a – 5.1a
- HP / hp-ux10.24 – 10.24
- HP / hp-ux10.10 – 10.10
- HP / hp-ux10.20 – 10.20
- HP / hp-ux11.00 – 11.00
- HP / hp-ux11.11 – 11.11
- ibm / aix4.3.3 – 4.3.3
- ibm / aix5.1 – 5.1
- sgi / irix6.5.7 – 6.5.7
- sgi / irix6.5.8 – 6.5.8
- sgi / irix6.5.9 – 6.5.9
- sgi / irix6.5.10 – 6.5.10
- sgi / irix6.5.11 – 6.5.11
- sgi / irix6.5.12 – 6.5.12
- sgi / irix6.5.13 – 6.5.13
- sgi / irix6.5.14 – 6.5.14
- sgi / irix6.5.15 – 6.5.15
- sgi / irix6.5.16 – 6.5.16
- sgi / irix5.2 – 5.2
- sgi / irix5.3 – 5.3
- sgi / irix6.0 – 6.0
- sgi / irix6.0.1 – 6.0.1
- sgi / irix6.1 – 6.1
- sgi / irix6.2 – 6.2
- sgi / irix6.3 – 6.3
- sgi / irix6.4 – 6.4
- sgi / irix6.5 – 6.5
- sgi / irix6.5.1 – 6.5.1
- sgi / irix6.5.2 – 6.5.2
- sgi / irix6.5.3 – 6.5.3
- sgi / irix6.5.4 – 6.5.4
- sgi / irix6.5.5 – 6.5.5
- sgi / irix6.5.6 – 6.5.6
- sun / solaris2.6 – 2.6
- sun / solaris9.0 – 9.0
- sun / sunos5.5.1 – 5.5.1
- sun / sunos5.7 – 5.7
- sun / sunos5.8 – 5.8
- xi_graphics / dextop2.1 – 2.1
References
- MISCftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.28/CSSA-2002-SCO.28.txt
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2002-20.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=102635906423617&w=2
- MISChttp://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0207-199
- MISChttp://archives.neohapsis.com/archives/aix/2002-q3/0002.html
- MISChttp://archives.neohapsis.com/archives/aix/2002-q3/0002.html
- MISChttp://www.kb.cert.org/vuls/id/299816
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20021101-01-P
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A175
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A80
- MISChttp://www.securityfocus.com/bid/5083
- MISChttp://www.iss.net/security_center/static/9527.php
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2770