superprobe Buffer Overflow Vulnerability
BID:364
Info
superprobe Buffer Overflow Vulnerability
| Bugtraq ID: | 364 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1489 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 04 1997 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | First posted to BugTraq by Solar <[email protected]> on March 4, 1997. |
| Vulnerable: |
Slackware Linux 3.1 |
| Not Vulnerable: | |
Discussion
superprobe Buffer Overflow Vulnerability
superprobe is an program supplied with XFree86 that helps determine video hardware. It is shipped with Slackware Linux 3.1 and is installed setuid root. There is an exploitable strcpy buffer overflow in the TestChip() function which allows for a trivial local root compromise.
superprobe is an program supplied with XFree86 that helps determine video hardware. It is shipped with Slackware Linux 3.1 and is installed setuid root. There is an exploitable strcpy buffer overflow in the TestChip() function which allows for a trivial local root compromise.
Exploit / POC
References
superprobe Buffer Overflow Vulnerability
References:
References: