Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

KDE Network RESLISA LOGNAME Local Buffer Overflow Vulnerability

A buffer overflow vulnerability has been reported for resLISa. The vulnerability results due to inadequate checks on the LOGNAME environment variable.

An attacker can exploit this vulnerability by setting a LOGNAME environment variable with an overly long value. When the attacker invokes resLISa, it will result in the creation of a raw socket that the attacker will have access to.

resLISa is typically installed as a setUID root binary.







 

Privacy Statement
Copyright 2008, SecurityFocus