Secunia Advisory SA10019SCO OpenServer Xsco Vulnerabilities
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Description
SCO has acknowledged some older vulnerabilities in the "Xsco" X11 server for OpenServer, which can be exploited by malicious, local users to escalate their privileges on a vulnerable system. A boundary error in the processing of the "-co" command line parameters can be exploited to cause a buffer overflow. This may allow execution of arbitrary code with "root" privileges. An error in the MIT-SHM extension in all X servers that are running as root can be exploited to read and write arbitrary shared memory segments on a vulnerable system. This can result in a DoS (Denial of Service) or allow privilege escalation. The vulnerabilities affect versions 5.0.5, 5.0.6, and 5.0.7. Solution ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.26/CSSA-2003-SCO.26.txt Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||
141 views | ![]() |
| Ubuntu update for thunderbird | |
114 views | ![]() |
| Debian update for php5 | |