Vector: | Local |
Severity: | Low |
Patch: | Unpatched |
Impact: | Escalation of Privileges |
Software: | IBM U2 UniVerse 10.x |
A remote code execution vulnerability was found in IBM U2 UniVerse "uvrestore".
Buffer overflow vulnerability exists in the "uvrestore" utility when handling command line options. An attacker can cause a buffer overflow and may potentially allow execution of arbitrary code with "root" privileges. However, this has not been proven.
Links: http://www.secnetops.com/research/advisories/SRT2003-07-07-0913.txt