PT-2007-1877 · Gxine · Gxine

Publicado

2007-01-23

·

Atualizado

2017-07-29

·

CVE-2007-0406

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gxine versions 0.5.9 and earlier
Description The issue is related to multiple buffer overflows in certain functions within gxine, specifically in the main function in client.c, and the server setup and server client connect functions in server.c. This can be exploited by local users via a long HOME environment variable, potentially leading to a denial of service (daemon crash) or privilege escalation.
Recommendations For gxine versions 0.5.9 and earlier, consider restricting the length of the HOME environment variable to prevent buffer overflows until a patch is available. As a temporary workaround, limiting the privileges of the gxine daemon may also help minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0406

Produtos afetados

Gxine