SuSE YaST Local Buffer Overflow Vulnerability
BID:14861
Info
SuSE YaST Local Buffer Overflow Vulnerability
| Bugtraq ID: | 14861 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 16 2005 12:00AM |
| Updated: | Sep 16 2005 12:00AM |
| Credit: | <[email protected]> discovered this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Desktop 1.0 S.u.S.E. beagle 10.0 |
| Not Vulnerable: | |
Discussion
SuSE YaST Local Buffer Overflow Vulnerability
SuSE YaST is affected by a local buffer overflow vulnerability.
A local attacker may exploit this issue to execute arbitrary code with superuser privileges.
SuSE YaST is affected by a local buffer overflow vulnerability.
A local attacker may exploit this issue to execute arbitrary code with superuser privileges.
Exploit / POC
SuSE YaST Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof of concept example is available:
=Loc: 1 AAAAAAAA["A"x515]AAA3ddiag-0.724-3.i586.rpm
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof of concept example is available:
=Loc: 1 AAAAAAAA["A"x515]AAA3ddiag-0.724-3.i586.rpm
Solution / Fix
SuSE YaST Local Buffer Overflow Vulnerability
Solution:
SUSE has released advisory SUSE-SR:2005:022 to address this and other issues. Please see the referenced advisory for more information.
Solution:
SUSE has released advisory SUSE-SR:2005:022 to address this and other issues. Please see the referenced advisory for more information.
References
SuSE YaST Local Buffer Overflow Vulnerability
References:
References: