Vulnerabilities > CVE-2005-3566 - Local Buffer Overflow vulnerability in VERITAS Cluster Server for UNIX

047910
CVSS 4.3 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
symantec-veritas
exploit available

Summary

Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.

Vulnerable Configurations

Part Description Count
Application
Symantec_Veritas
40

Exploit-Db

descriptionVeritas Storage Foundation 4.0 VCSI18N_LANG Local Overflow Exploit. CVE-2005-3566. Local exploit for linux platform
idEDB-ID:1316
last seen2016-01-31
modified2005-11-12
published2005-11-12
reporterKevin Finisterre
sourcehttps://www.exploit-db.com/download/1316/
titleVeritas Storage Foundation 4.0 VCSI18N_LANG Local Overflow Exploit