LibNewt Library Buffer Overflow Vulnerability
BID:4393
Info
LibNewt Library Buffer Overflow Vulnerability
| Bugtraq ID: | 4393 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 28 2002 12:00AM |
| Updated: | Mar 28 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Wu Tao <[email protected]>. |
| Vulnerable: |
Redhat Linux 7.2 ia64 Redhat Linux 7.2 i386 Redhat Linux 7.2 alpha Redhat Linux 7.1 ia64 Redhat Linux 7.1 i386 Redhat Linux 7.1 alpha Redhat Linux 7.0 sparc Redhat Linux 7.0 i386 Redhat Linux 7.0 alpha Redhat Linux 6.2 sparc Redhat Linux 6.2 i386 Redhat Linux 6.2 alpha |
| Not Vulnerable: | |
Discussion
LibNewt Library Buffer Overflow Vulnerability
Libnewt is a freely available, open source graphics library for text screens. It is available for use with Linux operating systems.
The newt library does not properly check bounds on some data used by the library. In a setuid program linked against the library, a user could exploit this condition to execute arbitrary code.
Libnewt is a freely available, open source graphics library for text screens. It is available for use with Linux operating systems.
The newt library does not properly check bounds on some data used by the library. In a setuid program linked against the library, a user could exploit this condition to execute arbitrary code.
Exploit / POC
LibNewt Library Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
LibNewt Library Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
LibNewt Library Buffer Overflow Vulnerability
References:
References: