vendor:
Tru64 UNIX
by:
stripey
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Tru64 UNIX
Affected Version From: Tru64 UNIX V5.0 (Rev. 910)
Affected Version To: Tru64 UNIX V5.0 (Rev. 910)
Patch Exists: YES
Related CWE: N/A
CPE: o:hp:tru64_unix
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: UNIX
2002
Buffer Overflow in Tru64
A buffer overflow has been discovered in a number of Tru64 binaries. Attackers may exploit this via an overly long value for the NLSPATH environment variable. Because of this flaw, a local attacker may be able to execute arbitrary instructions. As a result, the attacker may be able to execute malicious code and elevate privileges.
Mitigation:
Limit the length of the NLSPATH environment variable and ensure that it is not set to an overly long value.