Zblast Local Username Buffer Overrun Vulnerability
BID:7836
Info
Zblast Local Username Buffer Overrun Vulnerability
| Bugtraq ID: | 7836 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 06 2003 12:00AM |
| Updated: | Jun 06 2003 12:00AM |
| Credit: | This vulnerability was reported by Vade 79 <[email protected]>. |
| Vulnerable: |
zblast zblast 1.2 |
| Not Vulnerable: | |
Discussion
Zblast Local Username Buffer Overrun Vulnerability
A vulnerability has been reported for zblast, an svgalib-based game. The problem occurs when copying data from a user-supplied environment variable into a static memory buffer. By storing excessive data within the variable, it may be possible for an attacker to corrupt process memory, ultimately resulting in the execution of arbitrary code.
A vulnerability has been reported for zblast, an svgalib-based game. The problem occurs when copying data from a user-supplied environment variable into a static memory buffer. By storing excessive data within the variable, it may be possible for an attacker to corrupt process memory, ultimately resulting in the execution of arbitrary code.
Exploit / POC
Zblast Local Username Buffer Overrun Vulnerability
An exploit has been released by v9[[email protected]]:
An exploit has been released by v9[[email protected]]:
References
Zblast Local Username Buffer Overrun Vulnerability
References:
References:
- Zblast Home Page (www.svgalib.org)
- linux)zblast/xzb[v1.2]: local buffer overflow. (games) (Vade 79
)