vendor:
UnixWare
by:
Brock Tellier
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: UnixWare
Affected Version From: UnixWare 7.1
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: UnixWare (specific versions not mentioned)
Not mentioned
UnixWare i20dialogd Buffer Overflow Vulnerability
i20dialogd daemon in UnixWare operating system is vulnerable to a buffer overflow attack. The authentication mechanism of the daemon does not perform bounds checking on the username/password buffers, allowing an attacker to overflow the buffer and execute arbitrary code. Exploit code needs to be base64 encoded before being sent to the server.
Mitigation:
Apply the vendor patch or upgrade to a non-vulnerable version of UnixWare. Additionally, restrict access to the vulnerable daemon and monitor network traffic for any malicious activity.