First published: Wed Jan 11 2006(Updated: )
Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cray UNICOS | =9.0.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0178 has not been assigned a specific severity rating but involves a format string vulnerability that could impact local users.
To mitigate CVE-2006-0178, consider updating to a later version of UNICOS that resolves this vulnerability.
CVE-2006-0178 affects users of Cray UNICOS version 9.0.2.2.
CVE-2006-0178 is caused by insufficient handling of format string specifiers in the /bin/ftp quote command.
As of now, there is no widely known exploit for CVE-2006-0178 due to its nature and typical usage context.