Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2005-3566


Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.


Published

2005-11-16T07:42:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.1

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application symantec_veritas cluster_server 2.2 Yes
Application symantec_veritas cluster_server 2.2_linux Yes
Application symantec_veritas cluster_server 2.2_linux_mp1p1 Yes
Application symantec_veritas cluster_server 2.2_mp1 Yes
Application symantec_veritas cluster_server 2.2_mp2 Yes
Application symantec_veritas cluster_server 3.5 Yes
Application symantec_veritas cluster_server 3.5_aix Yes
Application symantec_veritas cluster_server 3.5_hp-ux Yes
Application symantec_veritas cluster_server 3.5_hp-ux_update_1 Yes
Application symantec_veritas cluster_server 3.5_hp-ux_update_2 Yes
Application symantec_veritas cluster_server 3.5_mp1 Yes
Application symantec_veritas cluster_server 3.5_mp1j Yes
Application symantec_veritas cluster_server 3.5_mp2 Yes
Application symantec_veritas cluster_server 3.5_p1 Yes
Application symantec_veritas cluster_server 3.5_solaris Yes
Application symantec_veritas cluster_server 3.5_solaris_beta Yes
Application symantec_veritas cluster_server 3.5_solaris_mp1 Yes
Application symantec_veritas cluster_server 3.5_solaris_mp2 Yes
Application symantec_veritas cluster_server 3.5_solaris_mp3 Yes
Application symantec_veritas cluster_server 4.0_aix Yes
Application symantec_veritas cluster_server 4.0_aix_beta Yes
Application symantec_veritas cluster_server 4.0_linux Yes
Application symantec_veritas cluster_server 4.0_linux_beta Yes
Application symantec_veritas cluster_server 4.0_solaris Yes
Application symantec_veritas cluster_server 4.0_solaris_beta Yes
Application symantec_veritas cluster_server 4.0_solaris_mp1 Yes
Application symantec_veritas sanpoint_control_quickstart 3.5_solaris Yes
Application symantec_veritas storage_foundation 1.0_aix Yes
Application symantec_veritas storage_foundation 2.2_linux Yes
Application symantec_veritas storage_foundation 2.2_vmware_esx Yes
Application symantec_veritas storage_foundation 3.0_aix Yes
Application symantec_veritas storage_foundation 3.4_aix Yes
Application symantec_veritas storage_foundation 3.5_hp-ux Yes
Application symantec_veritas storage_foundation 3.5_solaris Yes
Application symantec_veritas storage_foundation 4.0_aix Yes
Application symantec_veritas storage_foundation 4.0_linux Yes
Application symantec_veritas storage_foundation 4.0_solaris Yes
Application symantec_veritas storage_foundation_cluster_file_system 4.0_aix Yes
Application symantec_veritas storage_foundation_cluster_file_system 4.0_linux Yes
Application symantec_veritas storage_foundation_cluster_file_system 4.0_solaris Yes

References