Dosemu S-Lang Vulnerability

BID:187

Info

Dosemu S-Lang Vulnerability

Bugtraq ID: 187
Class: Boundary Condition Error
CVE:
Remote: Unknown
Local: Unknown
Published: Jan 04 1999 12:00AM
Updated: Jan 04 1999 12:00AM
Credit: The vulnerability was first posted on Bugtraq by Trev ([email protected]) on Mon, 4 Jan 1999 06:26:52 +0000. You can find the original post at http://www.geek-girl.com/bugtraq/1999_1/0040.html
Vulnerable: SuSE Linux 5.1
SuSE Linux 5.0
Redhat Linux 5.2 i386
Redhat Linux 5.1
- Standard & Poors ComStock 4.2.4
Redhat Linux 5.0
Redhat Linux 4.2
Redhat Linux 4.1
Redhat Linux 4.0
Not Vulnerable:

Discussion

Dosemu S-Lang Vulnerability

Two buffer overflow conditions exist within RedHat and SuSe Linux allowing local users to gain root privilege. Default RedHat 5.2 does not allow regular users to rnu dosemu and so the vulnerability will be limited.

Exploit / POC

Dosemu S-Lang Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Dosemu S-Lang Vulnerability

Solution:
As noted by Erik Mouw ([email protected])

Last saturday, the Dosemu Team released Dosemu 0.99.6 which fixes the Slang hole. This is a development release, but the changes will also come in the next stable release, Dosemu 0.98.5. From the ChangeLog:

99/01/06 ver. 0.99.5.3 unofficial pre-release From Hans - upgraded to slang-1.2.2 because of buffer overrun exploits in 1.0.3. Verified, that _both_ exploits are fixed. - fixed (now) possible buffer overrun in verror (utilities.c), because slang-1.2.2 fixed its exploit by passing the involved printout via (*SLang_Exit_Error_Hook)() to _our_ hooking routine. (well, so we now have it ;-)

Dosemu 0.99.6 is available at: ftp://ftp.dosemu.org:/dosemu/Development/dosemu-0.99.6.tgz

People using the 0.98 stable release should not run Dosemu suid root. Remove the s-bit from the Dosemu binary and wait for the next stable 0.98.5 release.

There is some security related documentation for Dosemu available at http://www.dosemu.org/docs/README/0.98/README-3.html , although it is a bit outdated.

Note that any Dosemu version running suid root with DPMI enabled is inherently unsafe. A DPMI program in Dosemu is able to use Linux system calls, including system calls that require root privileges. The Dosemu Team is not able to fix this security hole; system administrators who are serious about security, should not install Dosemu suid-root. Dosemu can run non-suid on the Slangterminal, under X, in the background and even on serial lines (bbs'es for example).

References

Dosemu S-Lang Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report