PT-2006-2002 · Stlport · Stlport

Publicado

2006-03-02

·

Atualizado

2022-07-19

·

CVE-2006-0963

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions STLport version 5.0.2
Description The issue involves multiple buffer overflows that could potentially allow local users to execute arbitrary code. This is possible through long locale environment variables passed to a strcpy function call in c locale glibc2.c and through long arguments to unspecified functions in num put float.cpp.
Recommendations For STLport version 5.0.2, consider applying patches or updates that address the buffer overflows in c locale glibc2.c and num put float.cpp to prevent potential code execution. As a temporary workaround, consider restricting the length of locale environment variables and function arguments to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0963

Produtos afetados

Stlport