Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open_unix | Sco | 8.0 (including) | 8.0 (including) |
Unixware | Sco | 7.1.1 (including) | 7.1.1 (including) |
Unixware | Sco | 7.1.3 (including) | 7.1.3 (including) |