|
KDE Network RESLISA LOGNAME Local Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for resLISa. The vulnerability results due to inadequate checks on the LOGNAME environment variable. An attacker can exploit this vulnerability by setting a LOGNAME environment variable with an overly long value. When the attacker invokes resLISa, it will result in the creation of a raw socket that the attacker will have access to. resLISa is typically installed as a setUID root binary. |
|
|
Privacy Statement |