|
NetBSD talkd Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for the talkd service shipped with NetBSD. Reportedly, the talkd service does not perform proper bounds checking on inbound messages before copying data to a destination buffer. An attacker can exploit this vulnerability to obtain elevated privileges on a vulnerable system. As this vulnerability is due to a buffer overflow condition, it is possible for a malicious attacker to cause talkd to execute code. This, however, has not been confirmed. |
|
|
Privacy Statement |