WMCube/GDK Object File Buffer Overflow Vulnerability
BID:3706
Info
WMCube/GDK Object File Buffer Overflow Vulnerability
| Bugtraq ID: | 3706 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 17 2001 12:00AM |
| Updated: | Dec 17 2001 12:00AM |
| Credit: | This vulnerability was announced via Bugtraq by Gobbles <[email protected]> on December 17, 2001. |
| Vulnerable: |
Timecop WMCube/GDK 0.98 |
| Not Vulnerable: | |
Discussion
WMCube/GDK Object File Buffer Overflow Vulnerability
WMCube/GDK is a freely available, open source application for monitoring CPU load. It can be used with one, or multiple CPU's.
WMCube/GDK does not properly impose the limit of 64 byte object files hard-coded into the program. Because of this, it is possible for a local user to load an object file greater than 64 bytes, creating a buffer overflow. This overflow could be used to overwrite stack variables, including the return address, and execute arbitrary code.
A local attacker may gain egid 'kmem', which allows for reading of kernel memory. Elevation to root is imminent when attackers can read kmem.
WMCube/GDK is a freely available, open source application for monitoring CPU load. It can be used with one, or multiple CPU's.
WMCube/GDK does not properly impose the limit of 64 byte object files hard-coded into the program. Because of this, it is possible for a local user to load an object file greater than 64 bytes, creating a buffer overflow. This overflow could be used to overwrite stack variables, including the return address, and execute arbitrary code.
A local attacker may gain egid 'kmem', which allows for reading of kernel memory. Elevation to root is imminent when attackers can read kmem.
Exploit / POC
WMCube/GDK Object File Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WMCube/GDK Object File Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WMCube/GDK Object File Buffer Overflow Vulnerability
References:
References: