Man Utility MANPL Environment Variable Buffer Overrun Vulnerability
BID:8602
Info
Man Utility MANPL Environment Variable Buffer Overrun Vulnerability
| Bugtraq ID: | 8602 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 12 2003 12:00AM |
| Updated: | Sep 12 2003 12:00AM |
| Credit: | This vulnerability was reported by SNOSoft. |
| Vulnerable: |
Andries Brouwer man 1.5 m1 Andries Brouwer man 1.5 m Andries Brouwer man 1.5 l Andries Brouwer man 1.5 k Andries Brouwer man 1.5 j Andries Brouwer man 1.5 i2 Andries Brouwer man 1.5 i Andries Brouwer man 1.5 h1 |
| Not Vulnerable: |
Andries Brouwer man 1.5 m2 |
Discussion
Man Utility MANPL Environment Variable Buffer Overrun Vulnerability
It has been reported that the man utility may be prone to a buffer overrun condition, when handling environment variable data. The problem is said to occur due to insufficient bounds checking when handling data stored within the MANPL environment variables. As a result of this issue, a local attacker may be capable of executing arbitrary code with the privileges of man, typically setgid 'man'.
It has been reported that the man utility may be prone to a buffer overrun condition, when handling environment variable data. The problem is said to occur due to insufficient bounds checking when handling data stored within the MANPL environment variables. As a result of this issue, a local attacker may be capable of executing arbitrary code with the privileges of man, typically setgid 'man'.
Exploit / POC
Man Utility MANPL Environment Variable Buffer Overrun Vulnerability
SNOSoft has reported that they have working proof of concept exploit code, however this has not been made available to the public.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
SNOSoft has reported that they have working proof of concept exploit code, however this has not been made available to the public.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Man Utility MANPL Environment Variable Buffer Overrun Vulnerability
Solution:
This issue is said to have been addressed in man 1.5m2, however this information has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue is said to have been addressed in man 1.5m2, however this information has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Man Utility MANPL Environment Variable Buffer Overrun Vulnerability
References:
References: