vendor:
HP-UX
by:
prdelka
7,2
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: HP-UX
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: HP-UX
Unknown
HP-UX libc timezone environment overflow exploit
HP-UX libc contains an exploitable stack overflow in the handling of 'TZ' environment variable. The problem occurs due to insufficient bounds checking in the localtime_r() and related functions. Any suid or sgid program which uses the timezone functions can be used as an attack vector. This exploit uses 'su' to obtain root priviledges.
Mitigation:
Ensure that all programs that use the timezone functions are updated to the latest version.