CVE-2005-4076

Appfluent Technology Database IDS 2.0 - Local Buffer Overflow via APPFLUENT_HOME Environment Variable

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-4076. PoCs published by c0ntex.

AI-analyzed exploit summary This exploit leverages a stack-based buffer overflow in Appfluent Database IDS v2.0 via the $APPFLUENT_HOME environment variable. It uses a crafted environment variable to overflow the stack and execute arbitrary shellcode, leading to local privilege escalation to root when executed via sudo.

Description

Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable.

Exploits (1)

exploitdb WORKING POC VERIFIED
by c0ntex · clocalsolaris
https://www.exploit-db.com/exploits/1360

This exploit leverages a stack-based buffer overflow in Appfluent Database IDS v2.0 via the $APPFLUENT_HOME environment variable. It uses a crafted environment variable to overflow the stack and execute arbitrary shellcode, leading to local privilege escalation to root when executed via sudo.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Appfluent Database IDS v2.0
Auth required
Prerequisites: User must be in sudoers file with permission to run the watcher process · Sudo must honor environment variables (env_reset not set) · $APPFLUENT_HOME environment variable must be set
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Various Sources x_refsource_misc
http://open-security.org/advisories/14
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0253.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17947
Various Sources x_refsource_misc
http://mantis.pulltheplug.org/display.php?offset=8
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15755

Scores

EPSS 0.0102
EPSS Percentile 58.8%

Details

Status published
Products (1)
appfluent_technology/database_ids 2.0
Published Dec 08, 2005
Tracked Since Feb 18, 2026