Title: VERITAS Cluster Server for UNIX Local Buffer Overflow Vulnerability
Severity: HIGH
Description:
VERITAS Cluster Server is a commercial clustering product designed to manage a wide range of applications in a heterogeneous environment.
Versions of VERITAS Cluster Server for UNIX are susceptible to a local buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it into an insufficiently sized memory buffer.
This issue is due specifically to improper bounds checking of the 'VCSI18N_LANG' environment variable in multiple setuid root 'ha' binaries.
The following binaries are reported to be affected:
haagent
haalert
haattr
hacli
haclus
haconf
hadebug
hagrp
hahb
halog
hareg
hares
hastatus
hasys
hatype
hauser
tststew
This issue allows local attackers to execute arbitrary machine code with superuser privileges.
Affected Products:
- Veritas Software Cluster Server 2.2.0
- Veritas Software Cluster Server 2.2.0Linux
- Veritas Software Cluster Server 2.2.0Linux MP1P1
- Veritas Software Cluster Server 2.2.0MP1
- Veritas Software Cluster Server 2.2.0MP2
- Veritas Software Cluster Server 3.5.0
- Veritas Software Cluster Server 3.5.0AIX
- Veritas Software Cluster Server 3.5.0HP-UX
- Veritas Software Cluster Server 3.5.0HP-UX Update 1
- Veritas Software Cluster Server 3.5.0HP-UX Update 2
- Veritas Software Cluster Server 3.5.0MP1
- Veritas Software Cluster Server 3.5.0MP1J
- Veritas Software Cluster Server 3.5.0MP2
- Veritas Software Cluster Server 3.5.0P1
- Veritas Software Cluster Server 3.5.0Solaris
- Veritas Software Cluster Server 3.5.0Solaris BETA
- Veritas Software Cluster Server 3.5.0Solaris MP1
- Veritas Software Cluster Server 3.5.0Solaris MP2
- Veritas Software Cluster Server 3.5.0Solaris MP3
- Veritas Software Cluster Server 4.0.0AIX
- Veritas Software Cluster Server 4.0.0AIX Beta
- Veritas Software Cluster Server 4.0.0Linux
- Veritas Software Cluster Server 4.0.0Linux Beta
- Veritas Software Cluster Server 4.0.0Solaris
- Veritas Software Cluster Server 4.0.0Solaris BETA
- Veritas Software Cluster Server 4.0.0Solaris MP1
- Veritas Software SANPoint Control Quickstart 3.5.0Solaris
- Veritas Software Storage Foundation Cluster File System 4.0.0AIX
- Veritas Software Storage Foundation Cluster File System 4.0.0Linux
- Veritas Software Storage Foundation Cluster File System 4.0.0Solaris
- Veritas Software Storage Foundation For Oracle 3.0.0AIX
- Veritas Software Storage Foundation For Oracle 3.5.0Solaris
- Veritas Software Storage Foundation For Oracle 4.0.0AIX
- Veritas Software Storage Foundation For Oracle 4.0.0Solaris
- Veritas Software Storage Foundation For Sybase 4.0.0Solaris
- Veritas Software Storage Foundation For UNIX 2.2.0Linux
- Veritas Software Storage Foundation For UNIX 2.2.0VMWare ESX
- Veritas Software Storage Foundation For UNIX 3.4.0AIX
- Veritas Software Storage Foundation For UNIX 3.5.0HP-UX
- Veritas Software Storage Foundation For UNIX 3.5.0Solaris
- Veritas Software Storage Foundation For UNIX 4.0.0AIX
- Veritas Software Storage Foundation For UNIX 4.0.0Linux
- Veritas Software Storage Foundation For UNIX 4.0.0Solaris
- Veritas Software Storage Foundation for DB2 1.0.0AIX
- Veritas Software Storage Foundation for DB2 4.0.0AIX
- Veritas Software Storage Foundation for DB2 4.0.0Solaris
- Veritas Software Storage Foundation for Oracle RAC 3.5.0Solaris
- Veritas Software Storage Foundation for Oracle RAC 4.0.0AIX
- Veritas Software Storage Foundation for Oracle RAC 4.0.0Linux
- Veritas Software Storage Foundation for Oracle RAC 4.0.0Solaris
References:
- Kevin Finisterre: DMA[2005-1112a] - 'Veritas Storage Foundation VCSI18N_LANG buffer overflow'
- Symantec: SYM05-023 - VERITAS Cluster Server for UNIX: Local Access Buffer Overflow Vulner
- Symantec: Veritas SYM05-023 VERITAS Cluster Server for UNIX: Local Access Buffer Overflow
- Veritas: Cluster Server Page
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.