Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Hanterm Local Buffer Overflow Vulnerability

Hanterm is a replacement for xterm which includes Hangul support, used for Korean language systems.

A buffer overflow error exists in hanterm. If it is called locally with a maliciously constructed parameter, it is possible to overflow a buffer. This can result in the return address of a stack frame being overwritten, and lead to the execution of arbitrary code.

As hanterm runs suid root on some systems, exploitation of this vulnerability may result in a local root compromise.







 

Privacy Statement
Copyright 2008, SecurityFocus