Caldera OpenLinux libdb1 buffer overflow
| openlinux-libdb-bo (7427) |
Description:
Caldera OpenLinux is vulnerable to a buffer overflow in the libdb1 package. An attacker can exploit configuration errors in the snprintf and vsnprintf functions to overflow a buffer in libdb and execute arbitrary code on the system to gain root privileges.
Platforms Affected:
- SCO, Caldera OpenLinux Server 3.1
- SCO, Caldera OpenLinux Workstation 3.1
Remedy:
For Caldera OpenLinux Server and Workstation 3.1:
Upgrade to the latest version of db (2.7.7-12 or later), as listed in Caldera International, Inc. Security Advisory CSSA-2001-037.0. See References.
Consequences:
Gain Access
References:
- Caldera International, Inc. Security Advisory CSSA-2001-037.0, Linux - libdb buffer overflow problem at ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2001-037.0.txt.
- BID-3497: LibDB SNPrintF Buffer Overflow Vulnerability
- CVE-2001-0850: A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow.
Reported:
Oct 30, 2001
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
