Date Discovered: 10 Jan 2003
Date Published: 10 Jan 2003
Last Updated: 18 Oct 2004
Vulnerability ID: 6968 Discovered By: anonymous
Exploitable Locally: Yes Exploitable Remotely: No
Impact: Local attackers can gain escalated privileges.
Root Cause: Software Vulnerability
UnixWare / Open UNIX ps command is vulnerable to a buffer overflow condition that may allow local attackers to gain escalated privileges. The flaw is due to improper bounds checking performed on command line arguments supplied by the user to the ps command. Because the ps command uses privileged calls, local attackers can exploit this flaw to overflow the buffer and execute arbitrary code with escalated privileges.
Back to top
Apply the patches provided by the vendor:UnixWare 7.1.1:ftp://ftp.sco.com/pub/updates/OpenUNIX/CSSA-2003-SCO.1.1/erg712109.pkg.ZOpen UNIX 8.0.0:ftp://ftp.sco.com/pub/updates/OpenUNIX/CSSA-2003-SCO.1.1/erg712109.pkg.ZUnixWare 7.1.3:ftp://ftp.sco.com/pub/updates/OpenUNIX/CSSA-2003-SCO.1.1/erg712109.pkg.ZVendor advisory:CSSA-2003-SCO.1CSSA-2003-SCO.1.1
Caldera: Caldera Open UNIX 8Santa Cruz Operation, Inc.: Unixware 7.1.1Santa Cruz Operation, Inc.: Unixware 7.1.3
Mitre CVE: CVE-2002-2270