20020919 iDEFENSE OSF1/Tru64 3.x vuln clarificationmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html CVE-2002-1616
Tru64 5 - 'su' Env Local Stack Overflow
Record summary
CVE-2002-1616 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTru64 5 - 'su' Env Local Stack OverflowExploitDB exploitby K2Not analyzed1 file
References
Showing 12 of 16SSRT2257Vendor advisory
http://archives.neohapsis.com/archives/tru64/2002-q3/0019.html blacksheepnetworks.com
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_su.txt VU#137555Third-party advisory
http://www.kb.cert.org/vuls/id/137555 VU#177067Third-party advisory
http://www.kb.cert.org/vuls/id/177067 VU#193347Third-party advisory
http://www.kb.cert.org/vuls/id/193347 VU#671627Third-party advisory
http://www.kb.cert.org/vuls/id/671627 VU#864083Third-party advisory
http://www.kb.cert.org/vuls/id/864083 20020902 Happy Labor Day from Snosoftmailing list
http://www.securityfocus.com/archive/1/290115 5379vdb entry
http://www.securityfocus.com/bid/5379 5380vdb entry
http://www.securityfocus.com/bid/5380 5381vdb entry
http://www.securityfocus.com/bid/5381