CVE-2005-3566
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6)…
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.
- CVSS 2.0
- 4.3 MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- symantec veritas/cluster server · symantec veritas/sanpoint control quickstart · symantec veritas/storage foundation · symantec veritas/storage foundation cluster file system
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=113199516516880&w=2
- http://osvdb.org/20673
- http://secunia.com/advisories/17502Patch, Vendor Advisory
- http://securityreason.com/securityalert/174
- http://securityresponse.symantec.com/avcenter/security/Content/2005.11.08a.htmlPatch, Vendor Advisory
- http://securitytracker.com/id?1015169Patch
- http://www.securityfocus.com/bid/15349Exploit
- http://www.vupen.com/english/advisories/2005/2350
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22986
- http://marc.info/?l=bugtraq&m=113199516516880&w=2
- http://osvdb.org/20673
- http://secunia.com/advisories/17502Patch, Vendor Advisory
- http://securityreason.com/securityalert/174
- http://securityresponse.symantec.com/avcenter/security/Content/2005.11.08a.htmlPatch, Vendor Advisory
- http://securitytracker.com/id?1015169Patch
- http://www.securityfocus.com/bid/15349Exploit
- http://www.vupen.com/english/advisories/2005/2350
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22986
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.