Linux Security Auditing Tool Multiple Buffer Overflow Vulnerabilities
BID:5150
Info
Linux Security Auditing Tool Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 5150 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 02 2002 12:00AM |
| Updated: | Jul 02 2002 12:00AM |
| Credit: | Published in the Linux Security Auditing Tool changelog. |
| Vulnerable: |
Linux Security Auditing Tool Linux Security Auditing Tool 0.5.7 |
| Not Vulnerable: |
Linux Security Auditing Tool Linux Security Auditing Tool 0.5.8 |
Discussion
Linux Security Auditing Tool Multiple Buffer Overflow Vulnerabilities
The Linux Security Auditing Tool (LSAT) is a program designed to scan a local Linux system for a number of potentially insecure configuration issues. A number of potential buffer overflow vulnerabilities exist in some versions of LSAT.
It may be possible for a local attacker to control some input to the LSAT process, and exploit this vulnerability to execute arbitrary code. Due to the nature of this program, it is likely that it will be executed by the root user.
The Linux Security Auditing Tool (LSAT) is a program designed to scan a local Linux system for a number of potentially insecure configuration issues. A number of potential buffer overflow vulnerabilities exist in some versions of LSAT.
It may be possible for a local attacker to control some input to the LSAT process, and exploit this vulnerability to execute arbitrary code. Due to the nature of this program, it is likely that it will be executed by the root user.
Exploit / POC
Linux Security Auditing Tool Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linux Security Auditing Tool Multiple Buffer Overflow Vulnerabilities
Solution:
An updated version is available:
Linux Security Auditing Tool Linux Security Auditing Tool 0.5.7
Solution:
An updated version is available:
Linux Security Auditing Tool Linux Security Auditing Tool 0.5.7
-
Linux Security Auditing Tool lsat-0.5.8.tgz
http://freshmeat.net/redir/lsat/28349/url_tgz/lsat-0.5.8.tgz
References
Linux Security Auditing Tool Multiple Buffer Overflow Vulnerabilities
References:
References:
- Linux Security Auditing Tool Homepage (Linux Security Auditing Tool)