HP-UX缓冲区溢出漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1107506 漏洞类型 缓冲区溢出
发布时间 2003-10-08 更新时间 2003-11-17
CVE编号 CVE-2003-0840 CNNVD-ID CNNVD-200311-081
漏洞平台 HP-UX CVSS评分 7.2
|漏洞来源
https://www.exploit-db.com/exploits/23236
https://www.securityfocus.com/bid/82742
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200311-081
|漏洞详情
HP-UX11.00的dtprintinfo以及可能其他的操作系统存在缓冲区溢出漏洞。本地用户借助超长DISPLAY环境变量提升根特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/8795/info

It has been reported that dtprintinfo, installed setuid root by default, is susceptible to a locally exploitable buffer overflow vulnerability. The condition is triggered when the value of the DISPLAY environment variable is set to a string exceeding 9777 bytes in length. The vulnerability may allow for local attackers to gain root privileges on the affected host. 

export DISPLAY="`perl -e 'printf "A" x 9777'`"
|受影响的产品
HP HP-UX 11.0
|参考资料

来源:BUGTRAQ
名称:20031008HPUXdtprintinfobufferoverflowvulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106563181313571&w=2