15th Apr 2002 [SBWID-5261]
COMMAND
X11 linked binaries buffer overflow
SYSTEMS AFFECTED
Open UNIX 8.0.0
UnixWare 7.1.1
PROBLEM
In Caldera International [http://www.caldera.com] security advisory
[CSSA-2002-SCO.15] :
There is a buffer overflow in the X11 library such that any command
linked with it that accepts the -xrm option will core dump if a long
string is used as the argument. Any setuid setgid program that accepts
the -xrm option is vulnerable to attack.
SOLUTION
Open UNIX 8.0.0
ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.15
UnixWare 7.1.1
ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.15