Youbin HOME Buffer Overflow Vulnerability
BID:7503
Info
Youbin HOME Buffer Overflow Vulnerability
| Bugtraq ID: | 7503 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0269 |
| Remote: | No |
| Local: | Yes |
| Published: | May 06 2003 12:00AM |
| Updated: | Jul 11 2009 09:07PM |
| Credit: | Discovery of this vulnerability has been credited to Knud Erik Højgaard of dtors security research. |
| Vulnerable: |
youbin youbin 3.4 youbin youbin 3.0 youbin youbin 2.5 |
| Not Vulnerable: | |
Discussion
Youbin HOME Buffer Overflow Vulnerability
It has been reported that youbin is vulnerable to a locally exploitable buffer overflow. The problem is said to occur while processing environment variables. Specifically, an internal memory buffer may be overrun while handling a HOME environment variable containing excessive data. This condition may be exploited by attackers to ultimately execute instructions with the privileges of the youbin process, typically root.
It should be noted that although this vulnerability has been reported to affect youbin version 3.4, previous versions might also be affected.
It has been reported that youbin is vulnerable to a locally exploitable buffer overflow. The problem is said to occur while processing environment variables. Specifically, an internal memory buffer may be overrun while handling a HOME environment variable containing excessive data. This condition may be exploited by attackers to ultimately execute instructions with the privileges of the youbin process, typically root.
It should be noted that although this vulnerability has been reported to affect youbin version 3.4, previous versions might also be affected.
Exploit / POC
Youbin HOME Buffer Overflow Vulnerability
The following proof of concept has been supplied:
The following proof of concept has been supplied:
Solution / Fix
Youbin HOME Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.