Vulnerability Description
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Caldera | Unixware | 7.0 |
| Xi Graphics | Dextop | 2.1 |
| Caldera | Openunix | 8.0 |
| Compaq | Tru64 | 4.0f |
| Hp | Hp-Ux | 10.10 |
| Ibm | Aix | 4.3.3 |
| Sun | Solaris | 2.6 |
| Sun | Sunos | 5.5.1 |
References
- http://marc.info/?l=bugtraq&m=102917002523536&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F46366&zone_32=category
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY32792&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY32793&apar=only
- http://www.cert.org/advisories/CA-2002-26.htmlUS Government Resource
- http://www.iss.net/security_center/static/9822.php
- http://www.kb.cert.org/vuls/id/387387PatchThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/5444
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0207-199
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://marc.info/?l=bugtraq&m=102917002523536&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F46366&zone_32=category
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY32792&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY32793&apar=only
FAQ
What is CVE-2002-0679?
CVE-2002-0679 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
How severe is CVE-2002-0679?
CVE-2002-0679 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0679?
Check the references section above for vendor advisories and patch information. Affected products include: Caldera Unixware, Xi Graphics Dextop, Caldera Openunix, Compaq Tru64, Hp Hp-Ux.