PT-2002-1519 · Ecartis · Ecartis
Publicado
2002-06-11
·
Atualizado
2016-10-18
·
CVE-2002-0468
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ecartis versions 1.0.0 and earlier
Description
The issue concerns buffer overflows that can be exploited by local users to gain privileges. This can be achieved through a long command line argument that is not properly handled in core.c. Additionally, there might be bad uses of sprintf() in various files, including moderate.c, lcgi.c, fileapi.c, cookie.c, and codes.c, which could potentially lead to exploitation.
Recommendations
For Ecartis version 1.0.0 and earlier, consider restricting access to the command line argument and limiting the use of sprintf() in the mentioned files until a patch is available.
As a temporary workaround, consider disabling the execution of long command line arguments in core.c to minimize the risk of exploitation.
Restrict access to the files moderate.c, lcgi.c, fileapi.c, cookie.c, and codes.c to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ecartis