Description
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Affected products
- cde / cde1.0.1 – 1.0.1
- cde / cde1.0.2 – 1.0.2
- cde / cde1.1 – 1.1
- cde / cde1.2 – 1.2
- cde / cde2.0 – 2.0
- cde / cde2.1 – 2.1
- digital / unix4.0d – 4.0d
- digital / unix4.0e – 4.0e
- digital / unix4.0f – 4.0f
- ibm / aix4.1 – 4.1
- ibm / aix4.1.1 – 4.1.1
- ibm / aix4.1.2 – 4.1.2
- ibm / aix4.1.3 – 4.1.3
- ibm / aix4.1.4 – 4.1.4
- ibm / aix4.1.5 – 4.1.5
- ibm / aix4.2 – 4.2
- ibm / aix4.2.1 – 4.2.1
- ibm / aix4.3 – 4.3
- ibm / aix4.3.1 – 4.3.1
- ibm / aix4.3.2 – 4.3.2
- sun / solaris2.4 – 2.4
- sun / solaris2.5.1 – 2.5.1
- sun / solaris2.6 – 2.6
- sun / solaris7.0 – 7.0
- sun / sunos5.4 – 5.4
- sun / sunos5.5 – 5.5
- sun / sunos5.5.1 – 5.5.1
- sun / sunos5.7 – 5.7