J-Security Center

Title: Caldera Open Unix UIDAdmin Scheme Option Buffer Overflow Vulnerability

Severity: HIGH

Description:

Open Unix is the commercially available Unix derivative available from Caldera International. It was originally UnixWare avialable from Santa Cruz Operations.

The 'uidadmin' system utility, a component of the SCO ID mapping facilities, is shipped by default with Open Unix and installed setuid root. 'uidadmin' contains a locally exploitable buffer overflow vulnerability in it's handling of commandline arguments.

If the '-S' parameter is argumented with a long string, a buffer overflow occurs. This may result in the corruption of a function stack frame or other sensitive areas of memory.

It may be possible for attackers to exploit this condition to execute shellcode with effective root privileges.

Affected Products:

  • Caldera OpenUnix 8.0.0
  • Caldera UnixWare 0.0.07

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.