Eterm PATH_ENV Buffer Overflow Vulnerability
BID:7708
Info
Eterm PATH_ENV Buffer Overflow Vulnerability
| Bugtraq ID: | 7708 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0382 |
| Remote: | No |
| Local: | Yes |
| Published: | May 27 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to bazarr <[email protected]>. |
| Vulnerable: |
Eterm Eterm 0.9.2 Eterm Eterm 0.9.1 |
| Not Vulnerable: | |
Discussion
Eterm PATH_ENV Buffer Overflow Vulnerability
Eterm has been reported prone to a local buffer overflow vulnerability. Code execution with elevated privileges has been confirmed possible.
The issue is due to a lack of sufficient bounds checking performed on an environment variable that is copied into an internal memory buffer.
An attacker may exploit this vulnerability to have arbitrary shell code executed with elevated privileges. Code execution will occur in the context of the vulnerable Eterm, which may have setuid/setgid utmp or possibly root on some Unix/Linux distributions.
Eterm has been reported prone to a local buffer overflow vulnerability. Code execution with elevated privileges has been confirmed possible.
The issue is due to a lack of sufficient bounds checking performed on an environment variable that is copied into an internal memory buffer.
An attacker may exploit this vulnerability to have arbitrary shell code executed with elevated privileges. Code execution will occur in the context of the vulnerable Eterm, which may have setuid/setgid utmp or possibly root on some Unix/Linux distributions.
Exploit / POC
Eterm PATH_ENV Buffer Overflow Vulnerability
An exploit for this vulnerability is publicly available.
An exploit for this vulnerability is publicly available.
Solution / Fix
Eterm PATH_ENV Buffer Overflow Vulnerability
Solution:
Debian has released a revised advisory containing new updates that eliminate the vulnerability. The previous fixes introduced a non-security related bug. See advisory DSA-309-2 (in the reference section) for download links to these new fixes.
Eterm Eterm 0.9.2
Solution:
Debian has released a revised advisory containing new updates that eliminate the vulnerability. The previous fixes introduced a non-security related bug. See advisory DSA-309-2 (in the reference section) for download links to these new fixes.
Eterm Eterm 0.9.2
-
Debian eterm_0.9.2-0pre2002042903.2_alpha.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_alpha.deb -
Debian eterm_0.9.2-0pre2002042903.2_arm.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_arm.deb -
Debian eterm_0.9.2-0pre2002042903.2_hppa.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_hppa.deb -
Debian eterm_0.9.2-0pre2002042903.2_i386.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_i386.deb -
Debian eterm_0.9.2-0pre2002042903.2_ia64.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_ia64.deb -
Debian eterm_0.9.2-0pre2002042903.2_m68k.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_m68k.deb -
Debian eterm_0.9.2-0pre2002042903.2_mips.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_mips.deb -
Debian eterm_0.9.2-0pre2002042903.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_mipsel.deb -
Debian eterm_0.9.2-0pre2002042903.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_powerpc.deb -
Debian eterm_0.9.2-0pre2002042903.2_s390.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_s390.deb -
Debian eterm_0.9.2-0pre2002042903.2_sparc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/e/eterm/eterm_0.9.2-0pre2 002042903.2_sparc.deb