TerminatorX Multiple Command-Line and Environment Buffer Overrun Vulnerabilities
BID:8993
Info
TerminatorX Multiple Command-Line and Environment Buffer Overrun Vulnerabilities
| Bugtraq ID: | 8993 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 07 2003 12:00AM |
| Updated: | Nov 07 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "c0wboy@0x333" <[email protected]>. |
| Vulnerable: |
terminatorX terminatorX 3.81 |
| Not Vulnerable: | |
Discussion
TerminatorX Multiple Command-Line and Environment Buffer Overrun Vulnerabilities
It has been reported that TerminatorX may be prone to multiple vulnerabilities when handling command-line and environment variable data. As a result, an attacker may be capable of exploiting the application in a variety of ways to execute arbitrary code with elevated privileges. It should be noted that TerminatorX is not installed setuid by default, however the author recommends that users make the application setuid root.
It has been reported that TerminatorX may be prone to multiple vulnerabilities when handling command-line and environment variable data. As a result, an attacker may be capable of exploiting the application in a variety of ways to execute arbitrary code with elevated privileges. It should be noted that TerminatorX is not installed setuid by default, however the author recommends that users make the application setuid root.
Exploit / POC
TerminatorX Multiple Command-Line and Environment Buffer Overrun Vulnerabilities
Exploit code has been released and is available below:
Exploit code has been released and is available below:
Solution / Fix
TerminatorX Multiple Command-Line and Environment Buffer Overrun Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
TerminatorX Multiple Command-Line and Environment Buffer Overrun Vulnerabilities
References:
References:
- Project Homepage (terminatorX)
- Local PoC exploit terminatorX v3.81 ("demz"
) - terminatorX stack-based overflow (exploit) (li0n7
)