PT-2006-2002 · Stlport · Stlport
Published
2006-03-02
·
Updated
2022-07-19
·
CVE-2006-0963
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
STLport version 5.0.2
Description
The issue involves multiple buffer overflows that could potentially allow local users to execute arbitrary code. This is possible through long locale environment variables passed to a
strcpy function call in c locale glibc2.c and through long arguments to unspecified functions in num put float.cpp.Recommendations
For STLport version 5.0.2, consider applying patches or updates that address the buffer overflows in
c locale glibc2.c and num put float.cpp to prevent potential code execution.
As a temporary workaround, consider restricting the length of locale environment variables and function arguments to minimize the risk of exploitation.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stlport