|
|
|
![]() |
Vulnerability Note VU#322540HP-UX "rexec" command vulnerable to buffer overflow when supplied overly long command line argument to "-l" optionOverviewA buffer overflow vulnerability in the rexec program supplied in some versions of the HP-UX operating system could allow local users to gain privileged access.I. DescriptionThe rexec program allows local users to execute commands on remote servers. rexec calls the rexec subroutine to act as a client for the remote host's rexecd server.The rexec program includes a "-l" command-line option that allows an alternate login name to be specified on the remote host. The rexec program supplied with some versions of the HP-UX operating systems contains a buffer overflow in the handling of the username argument passed to the "-l" option. An overly long username causes the rexec program to segmentation fault and could allow a local attacker to execute commands of their choosing on the local system. Since the rexec program is normally setuid to root, these commands would be executed with root privileges.
Workarounds
References
Thanks to Davide Del Vecchio for reporting this vulnerability. This document was written by Chad R Dougherty.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||