Description
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.
Affected products
- cray / unicos9.0.2.2 – 9.0.2.2
Exploits & proofs of concept
- exploit-dbCray UNICOS /usr/bin/script - Command Line Argument Local Overflowby Micheal Turner
- exploit-dbCray UNICOS /etc/nu - '-c' Option Filename Processing Local Overflowby Micheal Turner
Updated 6m ago · 8 sources