CVE-2005-3566: Buffer Overflow
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18NLANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacliruncmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3566?
CVE-2005-3566 is rated as a high severity vulnerability due to its potential to allow local users to execute arbitrary code.
How do I fix CVE-2005-3566?
To mitigate CVE-2005-3566, you should upgrade to the latest version of Symantec Veritas Cluster Server that addresses this buffer overflow issue.
Who is affected by CVE-2005-3566?
CVE-2005-3566 affects local users of various versions of Symantec Veritas Cluster Server and Storage Foundation for UNIX systems.
What are the symptoms of CVE-2005-3566?
Symptoms of CVE-2005-3566 may include unexpected application crashes or unauthorized code execution in the affected systems.
Is there a workaround for CVE-2005-3566?
While the best approach is to apply the patch, limiting access to the affected components can serve as a temporary workaround for CVE-2005-3566.