Sun Grid Engine daemon multiple unspecified buffer overflows
| sge-daemon-bo (28083) |
Description:
The Sun Grid Engine (SGE) daemon is vulnerable to multiple unspecified buffer overflows. A local attacker could exploit these vulnerabilities to cause the qmaster or execd process to crash or possibly execute arbitrary code on the system with elevated privileges.
Platforms Affected:
- Sun, N1 Grid Engine 5.3
- Sun, N1 Grid Engine 6.0
Remedy:
Refer to Sun Alert ID: 102322 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Gain Privileges
References:
- Sun Alert ID: 102322, Security Vulnerability With Sun N1 Grid Engine Daemons at http://sunsolve.sun.com/search/document.do?assetkey=1-26-102322-1.
- BID-19218: Sun Solaris N1 Grid Engine Multiple Local Vulnerabilities
- CVE-2006-3941: Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate.
- OSVDB ID: 27639: Sun N1 Grid Engine Unspecified Local Overflows
- SA21185: Sun Grid Engine Unspecified Buffer Overflow Vulnerability
- SA22425: Avaya CMS / IR Sun Solaris ACK Storm Denial of Service
- SECTRACK ID: 1016607: Sun N1 Grid Engine Buffer Overflows Let Local Users Shutdown the Grid Service or Gain Elevated Privileges
- VUPEN/ADV-2006-3066: Sun N1 Grid Engine Daemons Unspecified Local Buffer Overflow and Privilege Escalation
Reported:
Jul 28, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
