PT-2006-2002 · Stlport · Stlport
Publicado
2006-03-02
·
Atualizado
2022-07-19
·
CVE-2006-0963
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
STLport version 5.0.2
Description
The issue involves multiple buffer overflows that could potentially allow local users to execute arbitrary code. This is possible through long locale environment variables passed to a
strcpy function call in c locale glibc2.c and through long arguments to unspecified functions in num put float.cpp.Recommendations
For STLport version 5.0.2, consider applying patches or updates that address the buffer overflows in
c locale glibc2.c and num put float.cpp to prevent potential code execution.
As a temporary workaround, consider restricting the length of locale environment variables and function arguments to minimize the risk of exploitation.Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Stlport