Exploitation Summary
EIP tracks 3 public exploits for CVE-1999-1008. PoCs published by zorgon, Larry W. Cashdollar, Brock Tellier.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in xsoldier-0.96 on Red Hat Linux 6.2 (Zoot). It uses a NOP sled and shellcode to achieve remote code execution by overflowing the buffer and overwriting the return address.
Description
xsoldier program allows local users to gain root access via a long argument.
Exploits (3)
This exploit targets a buffer overflow vulnerability in xsoldier-0.96 on Red Hat Linux 6.2 (Zoot). It uses a NOP sled and shellcode to achieve remote code execution by overflowing the buffer and overwriting the return address.
This exploit targets a buffer overflow vulnerability in the xsoldier game (setuid root) on FreeBSD 3.3 and Linux Mandrake. It overflows the -display option with a crafted buffer containing NOPs, shellcode, and a manipulated return address to execute arbitrary code with root privileges.
This exploit targets a buffer overflow vulnerability in the xsoldier binary (part of X11 games) on FreeBSD 3.3-RELEASE and Linux Mandrake. It leverages a long string supplied to the -display option to overwrite the return address and execute shellcode that drops a suid root shell in /bin/sh.