XFree86 XLOCALEDIR Local Buffer Overflow Vulnerability
BID:7002
Info
XFree86 XLOCALEDIR Local Buffer Overflow Vulnerability
| Bugtraq ID: | 7002 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 03 2003 12:00AM |
| Updated: | Mar 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to tarranta and dcryptr. |
| Vulnerable: |
XFree86 X11R6 4.2.1 XFree86 X11R6 4.2 .0 |
| Not Vulnerable: | |
Discussion
XFree86 XLOCALEDIR Local Buffer Overflow Vulnerability
Several XFree86 utilities may be prone to a buffer overflow condition. The vulnerability exists due to insufficient boundary checks performed by these utilities when referencing the XLOCALEDIR environment variable.
A local attacker can exploit this vulnerability by setting the XLOCALEDIR environment variable to an overly long value. When the vulnerable utilities are executed, the buffer overflow vulnerability will be triggered.
Several XFree86 utilities may be prone to a buffer overflow condition. The vulnerability exists due to insufficient boundary checks performed by these utilities when referencing the XLOCALEDIR environment variable.
A local attacker can exploit this vulnerability by setting the XLOCALEDIR environment variable to an overly long value. When the vulnerable utilities are executed, the buffer overflow vulnerability will be triggered.
Exploit / POC
XFree86 XLOCALEDIR Local Buffer Overflow Vulnerability
The following exploit was provided:
The following exploit was provided:
Solution / Fix
XFree86 XLOCALEDIR Local Buffer Overflow Vulnerability
Solution:
Conectiva has released an advisory (CLSA-2003:682) and fixes to address this issue. See referenced advisory for further detail.
Solution:
Conectiva has released an advisory (CLSA-2003:682) and fixes to address this issue. See referenced advisory for further detail.
References
XFree86 XLOCALEDIR Local Buffer Overflow Vulnerability
References:
References:
- CLSA-2003:682 (Conectiva)
- XFree86 Homepage (XFree86)