Hanterm Local Buffer Overflow Vulnerability
BID:4050
Info
Hanterm Local Buffer Overflow Vulnerability
| Bugtraq ID: | 4050 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0239 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by xperc <[email protected]>. |
| Vulnerable: |
Hanterm Hanterm 3.3.1 Hanterm Hanterm 3.3 |
| Not Vulnerable: | |
Discussion
Hanterm Local Buffer Overflow Vulnerability
Hanterm is a replacement for xterm which includes Hangul support, used for Korean language systems.
A buffer overflow error exists in hanterm. If it is called locally with a maliciously constructed parameter, it is possible to overflow a buffer. This can result in the return address of a stack frame being overwritten, and lead to the execution of arbitrary code.
As hanterm runs suid root on some systems, exploitation of this vulnerability may result in a local root compromise.
Hanterm is a replacement for xterm which includes Hangul support, used for Korean language systems.
A buffer overflow error exists in hanterm. If it is called locally with a maliciously constructed parameter, it is possible to overflow a buffer. This can result in the return address of a stack frame being overwritten, and lead to the execution of arbitrary code.
As hanterm runs suid root on some systems, exploitation of this vulnerability may result in a local root compromise.