PT-2004-1285 · Xsok · Xsok

Published

2004-01-22

·

Updated

2017-07-11

·

CVE-2004-0074

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xsok version 1.02
Description The issue is related to multiple buffer overflows that allow local users to gain privileges. This can be achieved via a long LANG environment variable, or a long -xsokdir command line argument.
Recommendations For xsok version 1.02, consider restricting the length of the LANG environment variable and the -xsokdir command line argument to prevent buffer overflows until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0074

Affected Products

Xsok