Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NetBSD talkd Buffer Overflow Vulnerability

A buffer overflow vulnerability has been reported for the talkd service shipped with NetBSD. Reportedly, the talkd service does not perform proper bounds checking on inbound messages before copying data to a destination buffer.

An attacker can exploit this vulnerability to obtain elevated privileges on a vulnerable system.

As this vulnerability is due to a buffer overflow condition, it is possible for a malicious attacker to cause talkd to execute code. This, however, has not been confirmed.







 

Privacy Statement
Copyright 2008, SecurityFocus