|
Hanterm Local Buffer Overflow Vulnerability
Hanterm is a replacement for xterm which includes Hangul support, used for Korean language systems. A buffer overflow error exists in hanterm. If it is called locally with a maliciously constructed parameter, it is possible to overflow a buffer. This can result in the return address of a stack frame being overwritten, and lead to the execution of arbitrary code. As hanterm runs suid root on some systems, exploitation of this vulnerability may result in a local root compromise. |
|
|
Privacy Statement |