Sponsored by
 |
|
|
|

New Vulnerability Found in CDE
By Dennis Fisher
2001-10-08
Article Views: 204
Article Rating:    / 0
| Rate This Article: |
|
| Add This Article To: |
|
|
Security researchers have found a vulnerability in a popular Unix GUI program that could enable an attacker to gain root privileges on a victim's computer. The problem stems from a format string vulnerability in the Common Desktop Environment, an open-souSecurity researchers have found a vulnerability in a popular Unix GUI program that could enable an attacker to gain root privileges on a victims computer.
The problem stems from a format string vulnerability in the Common Desktop Environment, an open-source GUI that runs on Unix and Linux operating systems.
Specifically, the ToolTalk message brokering services RPC (Remote Procedure Call) database servera component of the CDEmishandles a certain error condition.
As such, an attacker can craft an RPC request that can cause the specific error condition. He could then overwrite portions of the victims machines memory, enabling him to execute code with the privileges of the RPC database server, which is typically root, according to a CERT advisory on the flaw.
The vulnerability, which was discovered by Internet Security Systems Inc.s X-Force research team, affects numerous versions of Unix and Linux, including Caldera Inc.s UnixWare and Open Linux and IBMs AIX 4.3 and 5.1. For a complete list of the vulnerable Unix and Linux implementations, see the CERT advisory at www.cert.org.
Many of the affected vendors have already released patches and the others are working on them.
|
|
 |
 |
| FEATURED DISCOVERY TOOL |
New from Ziff Davis Enterprise, this interactive tutorial provides an immersive educational experience and a guided tour of HP’s broad range of storage solutions. Using the Interactive Discovery Tool, you control the sequence of topics and drill down to the most relevant content for your company’s needs. Each page includes links to insightful white papers, videos, eSeminars, and case studies highlighting the importance of efficient enterprise storage.
Click here to check it out today and take advantage of access to helpful assets that address:
- Reducing backup dataset sizes with deduplication
- Storage consolidation and virtualization
- Optimized file services
- Disk-to-tape and disk-to-disk backup and archiving
Visit now!
| |
Sponsored by
|
|
|
| DOWNLOADABLE ROI CALCULATORS & TOOLS FROM BASELINE |
Calculate Cost and ROI of Spam, VOIP, RFID, Sarbanes-Oxley and more...
Featured Calculators:
See More Tools!
By Category| Planners |Calculators | Quizzes
|
|
| |
 |
|
|
MOST READ LINUX & OPEN SOURCE STORIES PAST 7 DAYS
- No Linux & Open Source articles found published in the past 7 days.
MOST READ LINUX & OPEN SOURCE STORIES PAST 30 DAYS
|
 |
 |
 |
EWEEK E-MAIL NEWSLETTERS bring you reliable, timely
information to stay on top of the business of technology -- and
technology in business -- and get more out of the Web.
Make your choices and start your subscriptions today!
| 
|
 |
EWEEK RSS NEWS FEEDS contain a daily feed of our latest stories from over 30 different categories including Enterprise Apps, Business Intelligence, Security, VOIP and more!
Subscribe to our RSS feeds today for free...
| 
| |
|