Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FreeBSD and Linux Mandrake 'xsoldier' Buffer Overflow Vulnerability

Certain versions of FreeBSD (3.3 Confirmed) and Linux (Mandrake confirmed) ship with a vulnerable binary in their X11 games package. The binary/game in question, xsoldier, is a setuid root binary meant to be run via an X windows console.

The binary itself is subject to a buffer overflow attack (which may be launched from the command line) which can be launched to gain root privileges. The overflow itself is in the code written to handle the -display option and is possible to overflow by a user-supplied long string.

The user does not have to have a valid $DISPLAY to exploit this.







 

Privacy Statement
Copyright 2009, SecurityFocus