Upclient Command Line Argument Buffer Overflow Vulnerability
BID:7703
Info
Upclient Command Line Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 7703 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0408 |
| Remote: | No |
| Local: | Yes |
| Published: | May 27 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to Gino Thomas <[email protected]>. |
| Vulnerable: |
The Uptimes Project upclient 5.0 b7 |
| Not Vulnerable: |
The Uptimes Project upclient 5.0 b8 |
Discussion
Upclient Command Line Argument Buffer Overflow Vulnerability
upclient has been reported prone to a buffer overflow vulnerability when handling command line arguments of excessive length.
It is possible for a local attacker to seize control of the vulnerable application and have malicious arbitrary code executed in the context of upclient. Typically setuid kmem.
An attacker may harness elevated privileges obtained in this way to manipulate arbitrary areas in system memory through /dev/mem or /dev/kmem devices.
upclient has been reported prone to a buffer overflow vulnerability when handling command line arguments of excessive length.
It is possible for a local attacker to seize control of the vulnerable application and have malicious arbitrary code executed in the context of upclient. Typically setuid kmem.
An attacker may harness elevated privileges obtained in this way to manipulate arbitrary areas in system memory through /dev/mem or /dev/kmem devices.
Exploit / POC
Upclient Command Line Argument Buffer Overflow Vulnerability
The following proof of concept exploit has been provided by Gino Thomas:
The following proof of concept exploit has been provided by Gino Thomas: