PT-2008-6230 · Htop+1 · Htop+1
Steven M. Christey
·
Published
2008-11-14
·
Updated
2023-10-06
·
CVE-2008-5076
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
htop version 0.7
Description
The issue allows local users to potentially hide processes, modify arbitrary files, or have unspecified other impact by utilizing a process name that contains non-printable characters, referred to as "crazy control strings."
Recommendations
For htop version 0.7, consider updating to a newer version that addresses this issue, as the current version may allow malicious process names to cause unintended consequences. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Htop