CVE-2005-3533

osh < 1.7.14 - Buffer Overflow via Long Working Directory and Filename

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-3533. PoCs published by Charles Stevenson.

AI-analyzed exploit summary This exploit targets a buffer overflow in Operator Shell (osh) 1.7-13 by manipulating the current working directory and file name to overflow a fixed-size buffer. It uses shellcode to achieve root privilege escalation.

Description

Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Charles Stevenson · perllocallinux
https://www.exploit-db.com/exploits/1154

This exploit targets a buffer overflow in Operator Shell (osh) 1.7-13 by manipulating the current working directory and file name to overflow a fixed-size buffer. It uses shellcode to achieve root privilege escalation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Operator Shell (osh) 1.7-13
Auth required
Prerequisites: User must be in the 'operator' group · Target system must have osh installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Charles Stevenson · perllocallinux
https://www.exploit-db.com/exploits/788

This exploit targets a buffer overflow vulnerability in the Operator Shell (osh) 1.7-12, allowing local privilege escalation to root. It leverages a stack-based overflow in the `iopen()` function by manipulating memory layout and function pointers to execute arbitrary shellcode.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Operator Shell (osh) 1.7-12
Auth required
Prerequisites: Local access to a system with osh installed · User must be in the operator group · osh must be setuid root
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17967
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-918
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2812
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12455
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21576

Scores

EPSS 0.0115
EPSS Percentile 62.6%

Details

Status published
Products (1)
osh/osh < 1.7.14
Published Dec 11, 2005
Tracked Since Feb 18, 2026