Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:CDE-DTSPCD-OF

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

CDE dtspcd Overflow

Release Date

2003/04/25

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: CDE dtspcd Overflow


This signature detects attempts to exploit a known vulnerability against CDE, a Motif-based GUI for UNIX systems. Attackers can use dtspcd, a server program that listens on TCP/6112, to overflow the buffer in the libDtSvc library and gain administrative privileges. This signature can also trigger on Bittorent traffic running on TCP/6112.

Extended Description

CDE is a Motif-based graphical user environment for UNIX systems. It is shipped with a number of commercial systems. A buffer-overflow vulnerability in the 'dtspcd' component may allow a remote attacker to gain administrative privileges on the affected host. The overflow is believed to be in the libDtSvc library, which used by the 'Subprocess Control Service'. The overflow is exploitable through the 'dtspcd' service,a server utility that facilitates remote invocation of CDE utilities and commands. The 'dtspcd' service listens on TCP port 6112, runs with root privileges, and is enabled by default (through 'inetd') on many systems.

Affected Products

  • Caldera OpenUnix 8.0.0
  • Caldera UnixWare 7
  • Compaq Tru64 4.0.0 f
  • Compaq Tru64 4.0.0 g
  • Compaq Tru64 5.0.0
  • Compaq Tru64 5.0.0 a
  • Compaq Tru64 5.1.0
  • Compaq Tru64 5.1.0 a
  • HP HP-UX 10.10.0
  • HP HP-UX 10.20.0
  • HP HP-UX 11.0.0
  • HP HP-UX 11.11.0
  • HP HP-UX (VVOS) 10.24.0
  • HP HP-UX (VVOS) 11.0.0 4
  • HP HP-UX (VVOS) 11.0.4
  • IBM AIX 4.0.0
  • IBM AIX 4.1.0
  • IBM AIX 4.1.1
  • IBM AIX 4.1.2
  • IBM AIX 4.1.3
  • IBM AIX 4.1.4
  • IBM AIX 4.1.5
  • IBM AIX 4.2.0
  • IBM AIX 4.2.1
  • IBM AIX 4.3.0
  • IBM AIX 4.3.1
  • IBM AIX 4.3.2
  • IBM AIX 4.3.3
  • IBM AIX 5.1
  • Open Group CDE Common Desktop Environment 1.0.1
  • Open Group CDE Common Desktop Environment 1.0.2
  • Open Group CDE Common Desktop Environment 1.1.0
  • Open Group CDE Common Desktop Environment 1.2.0
  • Open Group CDE Common Desktop Environment 2.0.0
  • Open Group CDE Common Desktop Environment 2.1.0
  • SGI IRIX 6.1.0
  • SGI IRIX 6.2.0
  • SGI IRIX 6.3.0
  • SGI IRIX 6.4.0
  • SGI IRIX 6.5.0
  • SGI IRIX 6.5.1
  • SGI IRIX 6.5.10
  • SGI IRIX 6.5.11
  • SGI IRIX 6.5.12
  • SGI IRIX 6.5.13
  • SGI IRIX 6.5.2
  • SGI IRIX 6.5.3
  • SGI IRIX 6.5.4
  • SGI IRIX 6.5.5
  • SGI IRIX 6.5.6
  • SGI IRIX 6.5.7
  • SGI IRIX 6.5.8
  • SGI IRIX 6.5.9
  • Sun Solaris 2.4
  • Sun Solaris 2.4_x86
  • Sun Solaris 2.5
  • Sun Solaris 2.5.1
  • Sun Solaris 2.5.1_ppc
  • Sun Solaris 2.5.1_x86
  • Sun Solaris 2.5_x86
  • Sun Solaris 2.6
  • Sun Solaris 2.6_x86
  • Sun Solaris 7.0
  • Sun Solaris 7.0_x86
  • Sun Solaris 8 Sparc
  • Sun Solaris 8 X86
  • Xi Graphics DeXtop 2.1.0
  • Xi Graphics Maximum CDE 1.2.3

References

  • BugTraq: 3517
  • CERT: CA-2001-31
  • CVE: CVE-2001-0803

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out