PT-2004-1285 · Xsok · Xsok
Published
2004-01-22
·
Updated
2017-07-11
·
CVE-2004-0074
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
xsok version 1.02
Description
The issue is related to multiple buffer overflows that allow local users to gain privileges. This can be achieved via a long LANG environment variable, or a long -xsokdir command line argument.
Recommendations
For xsok version 1.02, consider restricting the length of the LANG environment variable and the -xsokdir command line argument to prevent buffer overflows until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xsok