TerminatorX Command-line Format String Vulnerability
BID:8992
Info
TerminatorX Command-line Format String Vulnerability
| Bugtraq ID: | 8992 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 07 2003 12:00AM |
| Updated: | Nov 07 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "c0wboy@0x333" <[email protected]>. |
| Vulnerable: |
terminatorX terminatorX 3.81 |
| Not Vulnerable: | |
Discussion
TerminatorX Command-line Format String Vulnerability
It has been reported that TerminatorX may be prone to a format string vulnerability when handling command-line parameters. As a result, an attacker may be capable of exploiting the application in a variety ways to execute arbitrary code with elevated privileges. It should be noted that TerminatorX is not installed setuid by default, however the author recommends that users make the application setuid root.
It has been reported that TerminatorX may be prone to a format string vulnerability when handling command-line parameters. As a result, an attacker may be capable of exploiting the application in a variety ways to execute arbitrary code with elevated privileges. It should be noted that TerminatorX is not installed setuid by default, however the author recommends that users make the application setuid root.
Exploit / POC
TerminatorX Command-line Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
TerminatorX Command-line Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.