XSOK LANG Environment Variable Local Buffer Overrun Vulnerability
BID:9341
Info
XSOK LANG Environment Variable Local Buffer Overrun Vulnerability
| Bugtraq ID: | 9341 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0074 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 30 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | This issue appears to have been discovered by Debian. |
| Vulnerable: |
xsok xsok 1.0 2 |
| Not Vulnerable: | |
Discussion
XSOK LANG Environment Variable Local Buffer Overrun Vulnerability
xsok is prone to a locally exploitable buffer overrun vulnerability due to insufficient bounds check of data supplied through the LANG environment variable. This could be exploited to execute arbitrary code with elevated privileges. The program is typically installed setgid games.
xsok is prone to a locally exploitable buffer overrun vulnerability due to insufficient bounds check of data supplied through the LANG environment variable. This could be exploited to execute arbitrary code with elevated privileges. The program is typically installed setgid games.
Exploit / POC
XSOK LANG Environment Variable Local Buffer Overrun Vulnerability
The following exploit was provided:
The following exploit was provided:
Solution / Fix
XSOK LANG Environment Variable Local Buffer Overrun Vulnerability
Solution:
This issue was also addressed with the release of Debian advisory DSA 405-1. Please see the referenced advisory for details on obtaining and applying fixes.
Solution:
This issue was also addressed with the release of Debian advisory DSA 405-1. Please see the referenced advisory for details on obtaining and applying fixes.
References
XSOK LANG Environment Variable Local Buffer Overrun Vulnerability
References:
References:
- xsok local games exploit ("c0wboy@0x333"
)