20020210 Unixware Message catalog exploit codemailing list
http://online.securityfocus.com/archive/1/255414 CVE-2002-0246
Caldera UnixWare 7.1.1 - Message Catalog Environment Variable Format String
Record summary
CVE-2002-0246 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCaldera UnixWare 7.1.1 - Message Catalog Environment Variable Format StringExploitDB exploitby jGgMNot analyzed1 file
References
4unixware-msg-catalog-format-string(8113)vdb entry
http://www.iss.net/security_center/static/8113.php 4060vdb entry
http://www.securityfocus.com/bid/4060 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0246