![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.10833 |
Category: | Gain root remotely |
Title: | dtspcd overflow |
Summary: | NOSUMMARY |
Description: | Description: The 'dtspcd' service is running. This service deals with the CDE interface for the X11 system. Some versions of this daemon are vulnerable to a buffer overflow attack which may allow an attacker to gain root privileges on this host. *** This warning might be a false positive, *** as no real overflow was performed Solution : See http://www.cert.org/advisories/CA-2001-31.html to determine if you are vulnerable or deactivate this service (comment out the line 'dtspc' in /etc/inetd.conf and restart the inetd process) Risk factor : High |
Cross-Ref: |
BugTraq ID: 3517 Common Vulnerability Exposure (CVE) ID: CVE-2001-0803 http://www.securityfocus.com/bid/3517 Caldera Security Advisory: CSSA-2001-SCO.30 ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/ http://www.cert.org/advisories/CA-2001-31.html http://www.cert.org/advisories/CA-2002-01.html CERT/CC vulnerability note: VU#172583 http://www.kb.cert.org/vuls/id/172583 COMPAQ Service Security Patch: SSRT541 http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml HPdes Security Advisory: HPSBUX0111-175 http://www.securityfocus.com/advisories/3651 ISS Security Advisory: 20011112 Multi-Vendor Buffer Overflow Vulnerability in CDE Subprocess Control Service http://xforce.iss.net/alerts/advise101.php https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74 SGI Security Advisory: 20011107-01-P ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P Sun Security Bulletin: 00214 http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214 XForce ISS Database: cde-dtspcd-bo(7396) https://exchange.xforce.ibmcloud.com/vulnerabilities/7396 |
Copyright | This script is Copyright (C) 2002 Renaud Deraison |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |