PT-2007-1877 · Gxine · Gxine
Published
2007-01-23
·
Updated
2017-07-29
·
CVE-2007-0406
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
gxine versions 0.5.9 and earlier
Description
The issue is related to multiple buffer overflows in certain functions within gxine, specifically in the main function in client.c, and the server setup and server client connect functions in server.c. This can be exploited by local users via a long HOME environment variable, potentially leading to a denial of service (daemon crash) or privilege escalation.
Recommendations
For gxine versions 0.5.9 and earlier, consider restricting the length of the HOME environment variable to prevent buffer overflows until a patch is available. As a temporary workaround, limiting the privileges of the gxine daemon may also help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gxine