CVE-2003-0034

mtink - Buffer Overflow via HOME Environment Variable

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0034. PoCs published by Karol Wiesek.

AI-analyzed exploit summary The provided text describes a local buffer overflow vulnerability in mtink due to insufficient bounds checking of the HOME environment variable. Exploitation could lead to arbitrary code execution with elevated privileges if mtink is installed setgid 'sys'.

Description

Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Karol Wiesek · textlocallinux
https://www.exploit-db.com/exploits/22189

The provided text describes a local buffer overflow vulnerability in mtink due to insufficient bounds checking of the HOME environment variable. Exploitation could lead to arbitrary code execution with elevated privileges if mtink is installed setgid 'sys'.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: mtink (version not specified)
No auth needed
Prerequisites: mtink installed with elevated privileges (e.g., setgid 'sys') · local access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2003:010
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1005959
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6656
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.idefense.com/advisory/01.21.03.txt

Scores

EPSS 0.0130
EPSS Percentile 66.8%

Details

Status published
Products (3)
jean-jacques_sarton/mtink 0.9.32
jean-jacques_sarton/mtink 0.9.33
jean-jacques_sarton/mtink 0.9.52
Published Feb 07, 2003
Tracked Since Feb 18, 2026