20020828 iDEFENSE Security Advisory: Linuxconf locally exploitable buffer overflowmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-08/0304.html CVE-2002-1506
Linuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (1)
Record summary
CVE-2002-1506 has a selected CVSS score of 7.2; EIP currently links 3 catalogued exploits.
Description
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBLinuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (1)ExploitDB exploitby RaiSeNot analyzed1 file
ExploitDBLinuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (2)ExploitDB exploitby David EndlerNot analyzed1 file
ExploitDBLinuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (3)ExploitDB exploitby syscallsNot analyzed1 file
References
620020828 iDEFENSE Security Advisory: Linuxconf locally exploitable buffer overflowmailing list
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0093.html linuxconf-linuxconflang-env-bo(9980)vdb entry
http://www.iss.net/security_center/static/9980.php 5585vdb entry
http://www.securityfocus.com/bid/5585 solucorp.qc.ca
http://www.solucorp.qc.ca/changes.hc?projet=linuxconf&version=1.28r4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1506