WMTV Buffer Overflow Vulnerability
BID:4054
Info
WMTV Buffer Overflow Vulnerability
| Bugtraq ID: | 4054 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0247 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This issue was publicized in a Debian Security Advisory on February 7th, 2002. |
| Vulnerable: |
wliang wmtv 0.6.5 |
| Not Vulnerable: | |
Discussion
WMTV Buffer Overflow Vulnerability
wmtv is a video4linux TV player for windowmaker. It runs on Linux and Unix variants using windowmaker. It ships with Debian GNU/Linux 2.2.
A number of buffer overflows exist in affected versions of wmtv. This may provide an opportunity for a local attacker to execute arbitrary attacked-supplied instructions.
wmtv is installed setuid root by default, and affected versions require these privileges to run. Successful exploitation of this issue will allow the local attacker to gain root privileges on a host running vulnerable versions of wmtv.
However, it should be noted that it has not been proven whether these issues are exploitable.
This appears to be a problem with the version of wmtp that ships with Debian/GNU Linux due to the permissions that are required to run vulnerable versions of the software.
wmtv is a video4linux TV player for windowmaker. It runs on Linux and Unix variants using windowmaker. It ships with Debian GNU/Linux 2.2.
A number of buffer overflows exist in affected versions of wmtv. This may provide an opportunity for a local attacker to execute arbitrary attacked-supplied instructions.
wmtv is installed setuid root by default, and affected versions require these privileges to run. Successful exploitation of this issue will allow the local attacker to gain root privileges on a host running vulnerable versions of wmtv.
However, it should be noted that it has not been proven whether these issues are exploitable.
This appears to be a problem with the version of wmtp that ships with Debian/GNU Linux due to the permissions that are required to run vulnerable versions of the software.
References
WMTV Buffer Overflow Vulnerability
References:
References: