|
|
|
![]() |
Vulnerability Note VU#798263Taylor UUCP Package fails to properly filter command line argumentsOverviewSeveral Linux/Unix systems ship with a utility package called Taylor UUCP. A component of the UUCP package, uuxqt, fails to properly filter arguments from the commands sent to it. This can allow an intruder to gain elevated privileges and execute commands with the privileges of uucp, usually root.I. DescriptionA component of the UUCP package, uuxqt, is a daemon that executes commands requested by uux either from the local system or from remote systems. Before executing the command, uuxqt is supposed to filter dangerous command arguments. It fails to properly filter command line arguments that are specified in their long format. This can allow an intruder to gain elevated privileges and execute commands.II. ImpactAn intruder can gain elevated privileges and execute commands.III. SolutionApply the patches and upgrades provided by your vendor.Systems Affected
Referenceshttp://www.securityfocus.com/bid/3312 This vulnerability was discovered by zen-parse. This document was written by Jason Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||