Vulnerability CVE-2017-6553


Published: 2017-04-29

Description:
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.

See advisories in our WLB2 database:
Topic
Author
Date
High
Quest Privilege Manager pmmasterd Buffer Overflow
m0t
14.05.2017

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Quest -> Privilege manager for unix 

 References:
https://0xdeadface.wordpress.com/2017/04/07/multiple-vulnerabilities-in-quest-privilege-manager-6-0-0-xx-cve-2017-6553-cve-2017-6554/
https://support.oneidentity.com/privilege-manager-for-unix/kb/SOL133824

Copyright 2024, cxsecurity.com

 

Back to Top