Linux color_xterm Buffer Overflow Vulnerability
BID:369
Info
Linux color_xterm Buffer Overflow Vulnerability
| Bugtraq ID: | 369 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 27 1997 12:00AM |
| Updated: | May 27 1997 12:00AM |
| Credit: | Message and exploit first posted to BugTraq by James Clement <[email protected]> on May 27, 1997. |
| Vulnerable: |
Slackware Linux 3.2 Slackware Linux 3.1 |
| Not Vulnerable: |
Slackware Linux 3.3 |
Discussion
Linux color_xterm Buffer Overflow Vulnerability
In Slackware Linux 3.1 and 3.2, the version of color xterm included is vulnerable to a buffer overflow attack that allows for a local user to gain root access.
In Slackware Linux 3.1 and 3.2, the version of color xterm included is vulnerable to a buffer overflow attack that allows for a local user to gain root access.
Exploit / POC
Linux color_xterm Buffer Overflow Vulnerability
Exploit available:
Exploit available:
Solution / Fix
Linux color_xterm Buffer Overflow Vulnerability
Solution:
Remove the suid bit from the /usr/X11R6/bin/color_xterm. This was fixed in Slackware Linux 3.3.
Solution:
Remove the suid bit from the /usr/X11R6/bin/color_xterm. This was fixed in Slackware Linux 3.3.
References
Linux color_xterm Buffer Overflow Vulnerability
References:
References: