CVE-2005-3566
VERITAS Cluster Server for UNIX < 4.0MP2 - Local Buffer Overflow via VCSI18N_LANG Environment Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3566. PoCs published by Kevin Finisterre.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Veritas Storage Foundation 4.0 via the VCSI18N_LANG environment variable. It executes arbitrary shellcode to spawn a shell by overflowing the buffer and overwriting the return address.
Description
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Veritas Storage Foundation 4.0 via the VCSI18N_LANG environment variable. It executes arbitrary shellcode to spawn a shell by overflowing the buffer and overwriting the return address.