XConq Multiple Environment Variable Buffer Overflow Vulnerabilities
BID:8307
Info
XConq Multiple Environment Variable Buffer Overflow Vulnerabilities
| Bugtraq ID: | 8307 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0607 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 29 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to Steve Kemp. |
| Vulnerable: |
Stanley T. Shebs Xconq 7.4.1 |
| Not Vulnerable: | |
Discussion
XConq Multiple Environment Variable Buffer Overflow Vulnerabilities
Multiple locally exploitable buffer overflows have been reported in xconq. This is due to insufficient bounds checking of data supplied via the USER and DISPLAY environment variables, and could allow execution of code in the context of the program, which is typically installed setgid 'games'.
This issue appears similar to BID 1495.
Multiple locally exploitable buffer overflows have been reported in xconq. This is due to insufficient bounds checking of data supplied via the USER and DISPLAY environment variables, and could allow execution of code in the context of the program, which is typically installed setgid 'games'.
This issue appears similar to BID 1495.
Exploit / POC
XConq Multiple Environment Variable Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
XConq Multiple Environment Variable Buffer Overflow Vulnerabilities
Solution:
Debian has released an advisory (DSA 354-1) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Stanley T. Shebs Xconq 7.4.1
Solution:
Debian has released an advisory (DSA 354-1) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Stanley T. Shebs Xconq 7.4.1
-
Debian xconq-common_7.4.1-2woody2_all.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq-common_7.4. 1-2woody2_all.deb -
Debian xconq-doc_7.4.1-2woody2_all.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq-doc_7.4.1-2 woody2_all.deb -
Debian xconq_7.4.1-2woody2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_alpha.deb -
Debian xconq_7.4.1-2woody2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_arm.deb -
Debian xconq_7.4.1-2woody2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_hppa.deb -
Debian xconq_7.4.1-2woody2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_i386.deb -
Debian xconq_7.4.1-2woody2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_ia64.deb -
Debian xconq_7.4.1-2woody2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_m68k.deb -
Debian xconq_7.4.1-2woody2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_mips.deb -
Debian xconq_7.4.1-2woody2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_mipsel.deb -
Debian xconq_7.4.1-2woody2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_powerpc.deb -
Debian xconq_7.4.1-2woody2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_s390.deb -
Debian xconq_7.4.1-2woody2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xconq/xconq_7.4.1-2wood y2_sparc.deb
References
XConq Multiple Environment Variable Buffer Overflow Vulnerabilities
References:
References: