GNU GNATS PR-Edit Command Line Option Heap Corruption Vulnerablity
BID:8003
Info
GNU GNATS PR-Edit Command Line Option Heap Corruption Vulnerablity
| Bugtraq ID: | 8003 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 21 2003 12:00AM |
| Updated: | Jun 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to dong-h0un U [email protected]. |
| Vulnerable: |
GNU GNATS 3.0 02 |
| Not Vulnerable: | |
Discussion
GNU GNATS PR-Edit Command Line Option Heap Corruption Vulnerablity
A heap overflow vulnerability has been reported for the pr-edit utility of GNATS. The vulnerability occurs due to insufficient checks performed on the arguments to the '-d' commandline option.
Successful exploitation may result in the execution of attacker-supplied code with potentially elevated privileges.
A heap overflow vulnerability has been reported for the pr-edit utility of GNATS. The vulnerability occurs due to insufficient checks performed on the arguments to the '-d' commandline option.
Successful exploitation may result in the execution of attacker-supplied code with potentially elevated privileges.
References
GNU GNATS PR-Edit Command Line Option Heap Corruption Vulnerablity
References:
References:
- Gnats Homepage (GNU)
- GNATS (The GNU bug-tracking system) multiple buffer overflow vulnerabilities. ("dong-h0un U"
)