Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CDE LibDTHelp LOGNAME Environment Variable Local Buffer Overflow Vulnerability

A buffer overflow vulnerability is identified in CDE libDtHelp. Because of this, it may be possible for a local attacker to gain elevated privileges.

The problem is in the handling of data contained in a certain environment variable. Due to insufficient bounds checking, it is possible that system memory will be corrupted potentially overwriting sensitive values when the environment variable data is copied into memory.

A local attacker may exploit this vulnerability in order to execute arbitrary code in the context software that is linked to the vulnerable library.







 

Privacy Statement
Copyright 2009, SecurityFocus