Multiple Vendor Termcap tgetent() Buffer Overflow
BID:588
Info
Multiple Vendor Termcap tgetent() Buffer Overflow
| Bugtraq ID: | 588 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 18 1999 12:00AM |
| Updated: | Aug 18 1999 12:00AM |
| Credit: | This vulnerability was discovered by Kevin Vajk and the Linux Security Audit team. The advisory to this problem was released in a Redhat Security Bulletin posted to the Bugtraq mailing list on Tue, 17 Aug 1999. |
| Vulnerable: |
Slackware Linux 4.0 Slackware Linux 3.9 Slackware Linux 3.6 Slackware Linux 3.5 Slackware Linux 3.4 Slackware Linux 3.3 Slackware Linux 3.2 Redhat Linux 6.0 Redhat Linux 5.2 i386 Redhat Linux 5.1 Redhat Linux 5.0 Redhat Linux 4.2 Redhat Linux 4.1 Redhat Linux 4.0 |
| Not Vulnerable: |
Debian Linux 2.1 Caldera OpenLinux 2.2 |
Discussion
Multiple Vendor Termcap tgetent() Buffer Overflow
A buffer overflow existed in libtermcap's tgetent() function, which could cause the user to execute arbitrary code if they were able to supply their own termcap file. Versions of libtermcap 2.0.8 and earliear are vulnerable.
Under Red Hat Linux 5.2 and 4.2, this could lead to local users gaining root privileges, as xterm (as well as other possibly setuid programs) are linked against libtermcap. Under Red Hat Linux 6.0, xterm is not setuid root.
Debian and Caldera OpenLinux use the ncurses library instead of termcap and thus are not vulnerable.
A buffer overflow existed in libtermcap's tgetent() function, which could cause the user to execute arbitrary code if they were able to supply their own termcap file. Versions of libtermcap 2.0.8 and earliear are vulnerable.
Under Red Hat Linux 5.2 and 4.2, this could lead to local users gaining root privileges, as xterm (as well as other possibly setuid programs) are linked against libtermcap. Under Red Hat Linux 6.0, xterm is not setuid root.
Debian and Caldera OpenLinux use the ncurses library instead of termcap and thus are not vulnerable.
References
Multiple Vendor Termcap tgetent() Buffer Overflow
References:
References:
- Updates, Fixes, and Errata Page (RedHat)