PT-2008-4645 · Op · Op

Nico Golde

·

Publicado

2008-07-18

·

Atualizado

2017-08-08

·

CVE-2008-3229

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: op versions prior to Changeset 563
Description: A stack-based buffer overflow issue exists when xauth support is enabled, allowing local users to gain privileges via a long XAUTHORITY environment variable.
Recommendations: For versions prior to Changeset 563, consider disabling xauth support as a temporary workaround until a patch is available. Restrict access to the XAUTHORITY environment variable to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3229

Produtos afetados

Op