Tower Toppler HOME Environment Variable Local Buffer Overflow Vulnerability
BID:8132
Info
Tower Toppler HOME Environment Variable Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8132 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 08 2003 12:00AM |
| Updated: | Jul 08 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
Tower Toppler Tower Toppler 0.96 |
| Not Vulnerable: | |
Discussion
Tower Toppler HOME Environment Variable Local Buffer Overflow Vulnerability
A problem with the software may make elevation of privileges possible.
It has been reported that a buffer overflow exists in Tower Toppler. A local user may be able to exploit this issue to execute code with the privileges of the toppler program.
A problem with the software may make elevation of privileges possible.
It has been reported that a buffer overflow exists in Tower Toppler. A local user may be able to exploit this issue to execute code with the privileges of the toppler program.
Exploit / POC
Tower Toppler HOME Environment Variable Local Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept has been supplied:
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept has been supplied:
Solution / Fix
Tower Toppler HOME Environment Variable Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.