Vulnerability Name:

CVE-2002-0517 (CCN-7282)

Assigned:2001-10-15
Published:2001-10-15
Updated:2008-09-05
Summary:Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: Caldera International, Inc. Security Advisory CSSA-2001-SCO.26
Open UNIX 8, UnixWare 7: dtterm argument buffer overflow

Source: CALDERA
Type: UNKNOWN
CSSA-2002-SCO.15

Source: CCN
Type: BugTraq Mailing List, Tue Oct 02 2001 - 00:54:42 CDT
OpenUNIX 8 & Unixware possible local root

Source: BUGTRAQ
Type: UNKNOWN
20020108 xterm exploit in Unixware 7.0.1

Source: MITRE
Type: CNA
CVE-2002-0517

Source: XF
Type: Patch, Vendor Advisory
unixware-openunix-dtterm-bo(7282)

Source: XF
Type: UNKNOWN
x11-xrm-bo(8828)

Source: CCN
Type: US-CERT VU#169059
X11 vulnerable to buffer overflow in handling of -xrm option

Source: CERT-VN
Type: US Government Resource
VU#169059

Source: BUGTRAQ
Type: Vendor Advisory
20020108 dtterm exploit in Unixware 7.1.1

Source: BID
Type: Patch, Vendor Advisory
4502

Source: CCN
Type: BID-4502
Caldera X11 Library -xrm Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
unixware-openunix-dtterm-bo(7282)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:caldera:unixware:7.1.1:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:caldera:openunix:8.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2002-0517 (CCN-8828)

    Assigned:2002-04-11
    Published:2002-04-11
    Updated:2002-04-11
    Summary:Some Caldera Unix distributions are vulnerable to a buffer overflow in any program that uses the X11 library and accepts the -xrm option to execute arbitrary code. By supplying a long string as an argument with an -xrm option, a local attacker can overflow a buffer and execute arbitrary code on the system.
    CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
    Exploitability Metrics:Attack Vector (AV): Local
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): Low
    Integrity (I): Low
    Availibility (A): Low
    CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
    Exploitability Metrics:Access Vector (AV): Local
    Access Complexity (AC): Low
    Authentication (Au): None
    Impact Metrics:Confidentiality (C): Complete
    Integrity (I): Complete
    Availibility (A): Complete
    4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
    Exploitability Metrics:Access Vector (AV): Local
    Access Complexity (AC): Low
    Athentication (Au): None
    Impact Metrics:Confidentiality (C): Partial
    Integrity (I): Partial
    Availibility (A): Partial
    Vulnerability Consequences:Gain Privileges
    References:Source: CCN
    Type: Caldera International, Inc. Security Advisory CSSA-2002-SCO.15
    Open UNIX 8.0.0 UnixWare 7.1.1 : Buffer overflow in libX11 with -xrm

    Source: CCN
    Type: BugTraq Mailing List, Tue Jan 08 2002 - 00:08:40 CST
    xterm exploit in Unixware 7.0.1

    Source: CCN
    Type: BugTraq Mailing List, Tue Jan 08 2002 - 00:12:56 CST
    dtterm exploit in Unixware 7.1.1

    Source: MITRE
    Type: CNA
    CVE-2002-0517

    Source: CCN
    Type: US-CERT VU#169059
    X11 vulnerable to buffer overflow in handling of -xrm option

    Source: CCN
    Type: BID-4502
    Caldera X11 Library -xrm Buffer Overflow Vulnerability

    Source: XF
    Type: UNKNOWN
    x11-xrm-bo(8828)

    BACK
    caldera unixware 7.1.1
    caldera openunix 8.0