XShisen '-KCONV' Local Buffer Overflow Vulnerability
BID:8770
Info
XShisen '-KCONV' Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8770 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 06 2003 12:00AM |
| Updated: | Oct 06 2003 12:00AM |
| Credit: | Unknown |
| Vulnerable: |
XShisen XShisen 1.5.1 |
| Not Vulnerable: | |
Discussion
XShisen '-KCONV' Local Buffer Overflow Vulnerability
It has been reported that XShisen may be prone to a buffer overflow vulnerability due to insufficient boundary checking of user-supplied input. The problems are reported to exist due to the improper handling of user-supplied data from '-KCONV' command line parameter. It may be possible to cause a buffer overflow condition by supplying more than 100 bytes of data.
Successful exploitation may allow an attacker to ultimately execute arbitrary code in the context of the user who is running the vulnerable software in order to gain unauthorized access to a system.
XShisen version 1.51 has been reported to be prone to these issue however other versions may be affected as well.
It has been reported that XShisen may be prone to a buffer overflow vulnerability due to insufficient boundary checking of user-supplied input. The problems are reported to exist due to the improper handling of user-supplied data from '-KCONV' command line parameter. It may be possible to cause a buffer overflow condition by supplying more than 100 bytes of data.
Successful exploitation may allow an attacker to ultimately execute arbitrary code in the context of the user who is running the vulnerable software in order to gain unauthorized access to a system.
XShisen version 1.51 has been reported to be prone to these issue however other versions may be affected as well.
Solution / Fix
XShisen '-KCONV' Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.