what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

VB-97.14.scoterm

VB-97.14.scoterm
Posted Sep 14, 1999

The Santa Cruz Operation has discovered a security vulnerability in the implementation of scoterm.

SHA-256 | 376ee13af08019b9bc8c7e54e42a7c1e090f4d4e4d781f60417ce85f8daf17d3

VB-97.14.scoterm

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----

=============================================================================
CERT* Vendor-Initiated Bulletin VB-97.14
November 25, 1997

Topic: Vulnerability in /usr/bin/X11/scoterm
Source: The Santa Cruz Operation, Inc. (SCO)


To aid in the wide distribution of essential security information, the
CERT Coordination Center is forwarding the following information from
The Santa Cruz Operation, Inc. (SCO). SCO urges you to act on this
information as soon as possible. SCO contact information is included
in the forwarded text below; please contact them if you have any
questions or need further information.

=======================FORWARDED TEXT STARTS HERE============================

SCO Security Bulletin 97:02
November 20, 1997
Vulnerability in /usr/bin/X11/scoterm
- ----------------------------------------------------------------------------

The Santa Cruz Operation has discovered the following problem present in
our software:

I. Description

A security vulnerability in the implementation of scoterm has been
identified which could allow unprivileged users to gain unauthorized
root access to the system.

II. Impact

Any user with an account on the system may be able to execute arbitrary
commands with root privileges.

A program which exploits this vulnerability is in existence, although
we do not believe it is currently being distributed. There is a risk
that the exploit method may be revealed, so the patch should be applied
as soon as possible.

III. Releases

This problem exists on the following releases of SCO operating systems:

- SCO Open Desktop/Open Server 3.0
- SCO OpenServer 5.0

The following releases are not vulnerable, and no patch is necessary:

- SCO CMW+ 3.0
- SCO UnixWare 2.1

IV. Solution

SCO is providing interim patches to address this issue in the form
of a System Security Enhancement (SSE) package. The SSE package
includes patches for all operating systems listed above.

The SSE package is available for Internet download via anonymous
ftp, and from the SCOFORUM on Compuserve.

If you are for some reason unable to access or install the patches,
you should temporarily disable scoterm by running the following
command as the root user:

# chmod 0 /usr/bin/X11/scoterm


You can download the SSE package as follows:

Anonymous ftp (World Wide Web URL)
- --------------

ftp://ftp.sco.COM/SSE/sse009.ltr (cover letter, uncompressed)
ftp://ftp.sco.COM/SSE/sse009.tar.Z (new binaries, compressed tar file)

Compuserve
- -----------

GO SCOFORUM, and search the file library for these filenames:

SSE009.LTR (cover letter, compressed)
SSE009.TAZ (new binaries, compressed tar file)

Checksums
- ----------

sum -r

59495 4 sse009.ltr
15226 602 sse009.tar.Z


Updates:

This bulletin is available for anonymous ftp download from
ftp://ftp.sco.COM/SSE/security_bulletins/SB.97:02a, and will be
updated as new information becomes available.


Further Information:

If you have further questions, contact your support provider. If you
need to contact SCO, please send electronic mail to support@sco.COM, or
contact SCO as follows.

USA/Canada: 6am-5pm Pacific Time (PST/PDT)
-----------
1-800-347-4381 (voice)
1-408-427-5443 (fax)

Pacific Rim, Asia, and Latin American customers: 6am-5pm Pacific
------------------------------------------------ Time (PST/PDT)
1-408-425-4726 (voice)
1-408-427-5443 (fax)

Europe, Middle East, Africa: 9am-5:30pm UK Time (GMT/BST)
----------------------------
+44 (0)1923 816344 (voice)
+44 (0)1923 817781 (fax)


========================FORWARDED TEXT ENDS HERE=============================

If you believe that your system has been compromised, contact the CERT
Coordination Center or your representative in the Forum of Incident Response
and Security Teams (FIRST). See https://www.first.org/team-info/.

We strongly urge you to encrypt any sensitive information you send by email.
The CERT Coordination Center can support a shared DES key and PGP. Contact
the CERT staff for more information.

Location of CERT PGP key
ftp://ftp.cert.org/pub/CERT_PGP.key


CERT Contact Information
- -------------------------
Email cert@cert.org

Phone +1 412-268-7090 (24-hour hotline)
CERT personnel answer 8:30-5:00 p.m. EST
(GMT-5)/EDT(GMT-4), and are on call for
emergencies during other hours.

Fax +1 412-268-6989

Postal address
CERT Coordination Center
Software Engineering Institute
Carnegie Mellon University
Pittsburgh PA 15213-3890
USA

CERT publications, information about FIRST representatives, and other
security-related information are available from
https://www.cert.org/
ftp://ftp.cert.org/pub/

CERT advisories and bulletins are also posted on the USENET newsgroup
comp.security.announce

To be added to our mailing list for CERT advisories and bulletins, send your
email address to
cert-advisory-request@cert.org
In the subject line, type
SUBSCRIBE your-email-address



* Registered U.S. Patent and Trademark Office.

The CERT Coordination Center is part of the Software Engineering
Institute (SEI). The SEI is sponsored by the U. S. Department of Defense.


This file: ftp://ftp.cert.org/pub/cert_bulletins/VB-97.14.scoterm



-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBNHr9aXVP+x0t4w7BAQGxIQP/fHoEvpAaMgAxOvNuum97EN7QJG+GhetT
qdFV5qveyhgnJdlrQgf80lV3WsCYq9jh/KLpQIeszqLnmzWIitHW7JeThJeqZJPJ
0xpMdvftcM/o2073q7OcL195gyYvo+sbGUzA4KWfCAzV4OMDeS0ByQ07ViIh/XwS
R3A/rRR+KH8=
=1qyQ
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close