PT-2004-1285 · Xsok · Xsok
Publicado
2004-01-22
·
Atualizado
2017-07-11
·
CVE-2004-0074
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
xsok version 1.02
Description
The issue is related to multiple buffer overflows that allow local users to gain privileges. This can be achieved via a long LANG environment variable, or a long -xsokdir command line argument.
Recommendations
For xsok version 1.02, consider restricting the length of the LANG environment variable and the -xsokdir command line argument to prevent buffer overflows until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Xsok