Xvt Buffer Overflow Vulnerability
BID:2955
Info
Xvt Buffer Overflow Vulnerability
| Bugtraq ID: | 2955 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 02 2001 12:00AM |
| Updated: | Jul 02 2001 12:00AM |
| Credit: | Discovered by Christophe Bailleux <[email protected]>. |
| Vulnerable: |
John Bovey xvt 2.1 |
| Not Vulnerable: | |
Discussion
Xvt Buffer Overflow Vulnerability
Xvt is a terminal emulator for systems using X11R6. It is often installed setuid/setgid so that it runs with the enhanced privileges required to log user sessions.
Xvt contains a buffer overflow in it's handling of the '-name' argument.
An attacker can exploit this buffer overflow to exploit arbitrary code with the enhanced privileges of Xvt. On some systems Xvt is installed setuid root. This may not be the case for all systems.
Xvt is a terminal emulator for systems using X11R6. It is often installed setuid/setgid so that it runs with the enhanced privileges required to log user sessions.
Xvt contains a buffer overflow in it's handling of the '-name' argument.
An attacker can exploit this buffer overflow to exploit arbitrary code with the enhanced privileges of Xvt. On some systems Xvt is installed setuid root. This may not be the case for all systems.
Exploit / POC
Xvt Buffer Overflow Vulnerability
Christophe Bailleux provided exploit code.
Christophe Bailleux provided exploit code.
Solution / Fix
Xvt Buffer Overflow Vulnerability
Solution:
Remote the setuid/setgid bits from 'xvt' until a fix is available.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Remote the setuid/setgid bits from 'xvt' until a fix is available.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Xvt Buffer Overflow Vulnerability
References:
References: