AT Maliciously Formatted Time Heap Overflow Vulnerability
BID:3886
Info
AT Maliciously Formatted Time Heap Overflow Vulnerability
| Bugtraq ID: | 3886 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 16 2002 12:00AM |
| Updated: | Jan 16 2002 12:00AM |
| Credit: | This vulnerability was announced in a SuSE Security Advisory on January 16, 2002. |
| Vulnerable: |
at at 3.1.8 at at 3.1.7 |
| Not Vulnerable: | |
Discussion
AT Maliciously Formatted Time Heap Overflow Vulnerability
at is a freely available, open source scheduler package. It is included with various Unix and Linux operating systems, and maintained by public domain.
Under some circumstances, at does not correctly handle time input. A local user attempting to schedule a task via commandline execution and using a maliciously crafted time format can cause heap corruption in at. As the at program is installed setuid root in most implementations, this could result in the execution of arbitrary code with administrative privileges.
at is a freely available, open source scheduler package. It is included with various Unix and Linux operating systems, and maintained by public domain.
Under some circumstances, at does not correctly handle time input. A local user attempting to schedule a task via commandline execution and using a maliciously crafted time format can cause heap corruption in at. As the at program is installed setuid root in most implementations, this could result in the execution of arbitrary code with administrative privileges.