XPCD Home Environment Variable Local Buffer Overflow Vulnerability
BID:8370
Info
XPCD Home Environment Variable Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8370 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0649 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 18 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery credited to r-code. |
| Vulnerable: |
xpcd xpcd 2.0 8 |
| Not Vulnerable: | |
Discussion
XPCD Home Environment Variable Local Buffer Overflow Vulnerability
A problem in the handling of long strings in environment variables by xpcd may result in a buffer overflow condition. This may allow an attacker to gain unauthorized access to system resources.
A problem in the handling of long strings in environment variables by xpcd may result in a buffer overflow condition. This may allow an attacker to gain unauthorized access to system resources.
Exploit / POC
XPCD Home Environment Variable Local Buffer Overflow Vulnerability
Exploit contributed by r-code.
Exploit contributed by r-code.
Solution / Fix
XPCD Home Environment Variable Local Buffer Overflow Vulnerability
Solution:
Debian has released advisory DSA 368-1 to address this issue.
xpcd xpcd 2.0 8
Solution:
Debian has released advisory DSA 368-1 to address this issue.
xpcd xpcd 2.0 8
-
Debian xpcd-gimp_2.08-8woody1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_alpha.deb -
Debian xpcd-gimp_2.08-8woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_arm.deb -
Debian xpcd-gimp_2.08-8woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_hppa.deb -
Debian xpcd-gimp_2.08-8woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_i386.deb -
Debian xpcd-gimp_2.08-8woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_ia64.deb -
Debian xpcd-gimp_2.08-8woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_m68k.deb -
Debian xpcd-gimp_2.08-8woody1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_mips.deb -
Debian xpcd-gimp_2.08-8woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_mipsel.deb -
Debian xpcd-gimp_2.08-8woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_powerpc.deb -
Debian xpcd-gimp_2.08-8woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_s390.deb -
Debian xpcd-gimp_2.08-8woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-gimp_2.08-8wo ody1_sparc.deb -
Debian xpcd-svga_2.08-8woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd-svga_2.08-8wo ody1_i386.deb -
Debian xpcd_2.08-8woody1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ alpha.deb -
Debian xpcd_2.08-8woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ arm.deb -
Debian xpcd_2.08-8woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ hppa.deb -
Debian xpcd_2.08-8woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ i386.deb -
Debian xpcd_2.08-8woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ ia64.deb -
Debian xpcd_2.08-8woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ m68k.deb -
Debian xpcd_2.08-8woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ mipsel.deb -
Debian xpcd_2.08-8woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ powerpc.deb -
Debian xpcd_2.08-8woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ s390.deb -
Debian xpcd_2.08-8woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xpcd/xpcd_2.08-8woody1_ sparc.deb
References
XPCD Home Environment Variable Local Buffer Overflow Vulnerability
References:
References: