Multiple Vendor Termcap tgetent() Buffer Overflow

BID:588

Info

Multiple Vendor Termcap tgetent() Buffer Overflow

Bugtraq ID: 588
Class: Boundary Condition Error
CVE:
Remote: No
Local: Yes
Published: Aug 18 1999 12:00AM
Updated: Aug 18 1999 12:00AM
Credit: This vulnerability was discovered by Kevin Vajk and the Linux Security Audit team. The advisory to this problem was released in a Redhat Security Bulletin posted to the Bugtraq mailing list on Tue, 17 Aug 1999.
Vulnerable: Slackware Linux 4.0
Slackware Linux 3.9
Slackware Linux 3.6
Slackware Linux 3.5
Slackware Linux 3.4
Slackware Linux 3.3
Slackware Linux 3.2
Redhat Linux 6.0
Redhat Linux 5.2 i386
Redhat Linux 5.1
- Standard & Poors ComStock 4.2.4
Redhat Linux 5.0
Redhat Linux 4.2
Redhat Linux 4.1
Redhat Linux 4.0
Not Vulnerable: Debian Linux 2.1
Caldera OpenLinux 2.2

Discussion

Multiple Vendor Termcap tgetent() Buffer Overflow

A buffer overflow existed in libtermcap's tgetent() function, which could cause the user to execute arbitrary code if they were able to supply their own termcap file. Versions of libtermcap 2.0.8 and earliear are vulnerable.

Under Red Hat Linux 5.2 and 4.2, this could lead to local users gaining root privileges, as xterm (as well as other possibly setuid programs) are linked against libtermcap. Under Red Hat Linux 6.0, xterm is not setuid root.

Debian and Caldera OpenLinux use the ncurses library instead of termcap and thus are not vulnerable.

References

Multiple Vendor Termcap tgetent() Buffer Overflow

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report