CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unixware | Caldera | 7 (including) | 7 (including) |
Unixware | Caldera | 7.1.1 (including) | 7.1.1 (including) |
Unixware | Caldera | 7.1_.0 (including) | 7.1_.0 (including) |
Dextop | Xi_graphics | 2.1 (including) | 2.1 (including) |
Irix | Sgi | 5.2 (including) | 5.2 (including) |
Irix | Sgi | 5.3 (including) | 5.3 (including) |
Irix | Sgi | 6.0 (including) | 6.0 (including) |
Irix | Sgi | 6.0.1 (including) | 6.0.1 (including) |
Irix | Sgi | 6.1 (including) | 6.1 (including) |
Irix | Sgi | 6.2 (including) | 6.2 (including) |
Irix | Sgi | 6.3 (including) | 6.3 (including) |
Irix | Sgi | 6.4 (including) | 6.4 (including) |
Irix | Sgi | 6.5 (including) | 6.5 (including) |
Irix | Sgi | 6.5.1 (including) | 6.5.1 (including) |
Irix | Sgi | 6.5.2 (including) | 6.5.2 (including) |
Irix | Sgi | 6.5.3 (including) | 6.5.3 (including) |
Irix | Sgi | 6.5.4 (including) | 6.5.4 (including) |
Irix | Sgi | 6.5.5 (including) | 6.5.5 (including) |
Irix | Sgi | 6.5.6 (including) | 6.5.6 (including) |
Irix | Sgi | 6.5.7 (including) | 6.5.7 (including) |
Irix | Sgi | 6.5.8 (including) | 6.5.8 (including) |
Irix | Sgi | 6.5.9 (including) | 6.5.9 (including) |
Irix | Sgi | 6.5.10 (including) | 6.5.10 (including) |
Irix | Sgi | 6.5.11 (including) | 6.5.11 (including) |
Irix | Sgi | 6.5.12 (including) | 6.5.12 (including) |
Irix | Sgi | 6.5.13 (including) | 6.5.13 (including) |
Irix | Sgi | 6.5.14 (including) | 6.5.14 (including) |
Irix | Sgi | 6.5.15 (including) | 6.5.15 (including) |
Irix | Sgi | 6.5.16 (including) | 6.5.16 (including) |