Secunia Advisory SA10019

SCO OpenServer Xsco Vulnerabilities
Secunia Advisory SA10019
Track and eliminate the complete Vulnerability threat lifecycle

-

Track critical vulnerabilities affecting your infrastucture instantly
Release Date 2003-10-16
   
Popularity 7,278 views
Comments 0 comments

Criticality level Less criticalLess critical
Impact Exposure of system information
Exposure of sensitive information
Privilege escalation
DoS
Where Local system
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
   
Operating System
SCO OpenServer 5.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2002-0158 CVSS available in Customer Area
CVE-2002-0164 CVSS available in Customer Area
  

Description
SCO has acknowledged some older vulnerabilities in the "Xsco" X11 server for OpenServer, which can be exploited by malicious, local users to escalate their privileges on a vulnerable system.

A boundary error in the processing of the "-co" command line parameters can be exploited to cause a buffer overflow. This may allow execution of arbitrary code with "root" privileges.

An error in the MIT-SHM extension in all X servers that are running as root can be exploited to read and write arbitrary shared memory segments on a vulnerable system. This can result in a DoS (Denial of Service) or allow privilege escalation.

The vulnerabilities affect versions 5.0.5, 5.0.6, and 5.0.7.

Solution
Install latest packages:
Further details available in Customer Area

Original Advisory
ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.26/CSSA-2003-SCO.26.txt

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
Subject: SCO OpenServer Xsco Vulnerabilities
 
No posts yet

-

You must be logged in to post a comment.



footer
© 2002-2010 Secunia ApS • Weidekampsgade 14A, DK-2300 Copenhagen S, Denmark • +45 7020 5144 • Contact Us
Terms & Conditions and CopyrightReport vulnerability
CVE logo OTA logo First logo