|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
GCOS-III contains a flaw that may allow a local user to gain elevated privileges. The issue is due to the buffer space made available by the caller to the File System (FILSYS) modules not being zeroed out before return to the caller. By supplying a systematic value to the System Master Catalog (SMC), FILESYS would return an error but not zero the buffer, which could disclose sensitive information such as user login and passwords.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
GCOS-III
 |
Unknown or Unspecified |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|