CVE-2005-1396

Ce/Ceterm <2.5.4 - Local Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-1396. PoCs published by Kevin Finisterre.

AI-analyzed exploit summary This exploit targets a setuid vulnerability in the ARPUS/ce utility (CVE-2005-1396) by overflowing the XAPPLRESLANGPATH environment variable with shellcode to achieve local privilege escalation. The shellcode spawns a root shell by leveraging a buffer overflow and return address overwrite.

Description

Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Kevin Finisterre · perllocallinux
https://www.exploit-db.com/exploits/974

This exploit targets a setuid vulnerability in the ARPUS/ce utility (CVE-2005-1396) by overflowing the XAPPLRESLANGPATH environment variable with shellcode to achieve local privilege escalation. The shellcode spawns a root shell by leveraging a buffer overflow and return address overwrite.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: ARPUS/ce (version unspecified)
No auth needed
Prerequisites: Local access to the vulnerable system · Presence of the setuid ARPUS/ce binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Kevin Finisterre · clocallinux
https://www.exploit-db.com/exploits/973

This exploit leverages a vulnerability in the ARPUS/ce program (CVE-2005-1396) by manipulating the DISPLAY environment variable to prevent privilege dropping, then overwriting /etc/ld.so.preload with a malicious shared library to escalate privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: ARPUS/ce (versions up to ce-0260)
No auth needed
Prerequisites: Presence of vulnerable ARPUS/ce binary with setuid root · Write access to /tmp directory · Ability to execute /usr/bin/ce
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013855
Vendor Advisory vdb-entry x_refsource_osvdb
http://www.osvdb.org/16050
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15197

Scores

EPSS 0.0073
EPSS Percentile 49.3%

Details

Status published
Published May 03, 2005
Tracked Since Feb 18, 2026