exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

SCOSA-2005.45.txt

SCOSA-2005.45.txt
Posted Nov 3, 2005
Authored by SCO | Site sco.com

SCO Security Advisory - Cross-site scripting vulnerability in docview (htdig) under UnixWare 7.1.3 and UnixWare 7.1.4 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.

tags | advisory, remote, web, arbitrary, xss
systems | unixware
advisories | CVE-2005-0085
SHA-256 | 8948f1f7a616d3f968054e459f46c68794386b15c994b4b12f89f92fd3ea5f4a

SCOSA-2005.45.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

______________________________________________________________________________

SCO Security Advisory

Subject: UnixWare 7.1.3 UnixWare 7.1.4 : Cross-site Scripting Vulnerability in docview (htdig)
Advisory number: SCOSA-2005.45
Issue date: 2005 November 02
Cross reference: sr893246 fz531483 erg712807
CVE-2005-0085
______________________________________________________________________________


1. Problem Description

Cross-site scripting vulnerability in docview (htdig) allows
remote attackers to execute arbitrary web script or HTML via the
config parameter, which is not properly sanitized before it is
displayed in an error message.

The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CVE-2005-0085 to this issue.


2. Vulnerable Supported Versions

System Binaries
----------------------------------------------------------------------
UnixWare 7.1.3 /usr/bin/htsearch
UnixWare 7.1.4 /usr/bin/htsearch


3. Solution

The proper solution is to install the latest packages.


4. UnixWare 7.1.3

4.1 Location of Fixed Binaries

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.45/713


4.2 Verification

486315f201bc414087b9b8614174f85f erg712807.Z

md5 is available for download from
ftp://ftp.sco.com/pub/security/tools


4.3 Installing Fixed Binaries

Upgrade the affected binaries with the following sequence:

Download erg712807.Z to the /var/spool/pkg directory

# uncompress /var/spool/pkg/erg712807.Z
# pkgadd -d /var/spool/pkg/erg712807


5. UnixWare 7.1.4

5.1 Location of Fixed Binaries

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.45/714


5.2 Verification

86a153577d647ccf0c94e870fa817c32 erg712807.Z

md5 is available for download from
ftp://ftp.sco.com/pub/security/tools


5.3 Installing Fixed Binaries

Upgrade the affected binaries with the following sequence:

Download erg712807.Z to the /var/spool/pkg directory

# uncompress /var/spool/pkg/erg712807.Z
# pkgadd -d /var/spool/pkg/erg712807


6. References

Specific references for this advisory:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0085
https://securitytracker.com/id?1013078
https://xforce.iss.net/xforce/xfdb/19223

SCO security resources:
https://www.sco.com/support/security/index.html

SCO security advisories via email
https://www.sco.com/support/forums/security.html

This security fix closes SCO incidents sr893246 fz531483
erg712807.


7. Disclaimer

SCO is not responsible for the misuse of any of the information
we provide on this website and/or through our security
advisories. Our advisories are a service to our customers
intended to promote secure installation and use of SCO
products.


8. Acknowledgments

SCO would like to thank Michael Krax for reporting this
vulnerability.

______________________________________________________________________________
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (UnixWare)

iD8DBQFDaSBqaqoBO7ipriERAgd/AKCI86ak85GPTMdFfpxQz3caGbJ2VQCeJ4sr
Dl13BBed11W+ikgZu5ZDA8I=
=4CDB
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close