Minicom XModem Format String Vulnerability

BID:2681

Info

Minicom XModem Format String Vulnerability

Bugtraq ID: 2681
Class: Input Validation Error
CVE:
Remote: No
Local: Yes
Published: May 03 2001 12:00AM
Updated: May 03 2001 12:00AM
Credit: This vulnerability was announced to Bugtraq by zenith parsec <[email protected]> on May 3, 2001.
Vulnerable: minicom minicom 1.83.1
+ Caldera OpenLinux 2.4
- FreeBSD FreeBSD 4.2
- FreeBSD FreeBSD 3.5.1
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.1
+ Mandriva Linux Mandrake 7.0
+ Redhat Linux 7.0
+ Redhat Linux 6.2
+ SCO eDesktop 2.4
+ SCO eServer 2.3.1
+ Slackware Linux 7.1
+ Slackware Linux 7.0
+ SuSE Linux 7.1
+ SuSE Linux 7.0
+ SuSE Linux 6.4
minicom minicom 1.83 .0
+ Caldera OpenLinux 2.4
- FreeBSD FreeBSD 4.2
- FreeBSD FreeBSD 3.5.1
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.1
+ Mandriva Linux Mandrake 7.0
+ SCO eDesktop 2.4
+ SCO eServer 2.3.1
+ Slackware Linux 7.1
+ Slackware Linux 7.0
+ SuSE Linux 7.1
+ SuSE Linux 7.0
+ SuSE Linux 6.4
+ SuSE Linux 6.2
minicom minicom 1.82.1
- FreeBSD FreeBSD 4.2
- FreeBSD FreeBSD 3.5.1
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.1
+ Mandriva Linux Mandrake 7.0
+ Slackware Linux 7.1
+ Slackware Linux 7.0
+ SuSE Linux 7.1
+ SuSE Linux 7.0
+ SuSE Linux 6.4
Not Vulnerable: SCO eServer 2.3.1
Caldera OpenLinux eBuilder 3.0
Caldera OpenLinux 2.3

Discussion

Minicom XModem Format String Vulnerability

Minicom is a serial communication utility, often used to simplify dialup connections for UNIX hosts. It is included with many popular UNIX and UNIX derivative operating systems, and is a clone of the original Telix program for MS-DOS.

A problem in the design of the software makes it vulnerable to a format string attack. By executing the software, and attempting to send a file via xmodem with a format identifier in the name, it is possible exploit this format string vulnerability.

This makes it possible for a local user to gain an elevation of privileges equal to uucp.

Caldera Systems reports that OpenLinux does not permit exploitation of this vulnerability to yield root privilege to the attacker.

Exploit / POC

Minicom XModem Format String Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Minicom XModem Format String Vulnerability

Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.


minicom minicom 1.82.1

minicom minicom 1.83 .0

minicom minicom 1.83.1

References

Minicom XModem Format String Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report