Xfree缓冲区溢出漏洞

Xfree缓冲区溢出漏洞

漏洞ID 1106039 漏洞类型 缓冲区溢出
发布时间 2000-10-12 更新时间 2005-05-02
图片[1]-Xfree缓冲区溢出漏洞-安全小百科CVE编号 CVE-2000-0976
图片[2]-Xfree缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200012-173
漏洞平台 Unix CVSS评分 4.6
|漏洞来源
https://www.exploit-db.com/exploits/20294
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200012-173
|漏洞详情
XFree3.3.x版本中的xlib存在缓冲区溢出漏洞。本地用户可能借助超长DISPLAY环境变量或-display命令行参数执行任意命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/1805/info

A vulnerability exists in xlib, the C language interface to the X Window System protocol. 

When applications linked to the xlib library are run, user-supplied values for the DISPLAY environment variable (and the command-line argument -display) are stored in buffers of predefined length. It is not verified that the amount data is within the predefined size limits before it is copied onto the stack during function calls. 

Consequently it is possible for users to overwrite stack variables such as the calling function's return address with arbitrary values that can alter the program's flow of execution. 

While this vulnerability permits only numeric characters to be written to the stack, a successful exploit of this vulnerability can lead to partial overwriting of addresses and local variables.

cwsys$ DISPLAY=:`perl -e '{print "0"x128}'` xterm
Segmentation fault
cwsys$
|参考资料

来源:BID
名称:1805
链接:http://www.securityfocus.com/bid/1805
来源:BUGTRAQ
名称:20001012anotherXlibbufferoverflow
链接:http://archives.neohapsis.com/archives/bugtraq/2000-10/0211.html
来源:XF
名称:xfree-xlib-bo(5751)
链接:http://www.iss.net/security_center/static/5751.php
来源:SGI
名称:20020502-01-I
链接:ftp://patches.sgi.com/support/free/security/advisories/20020502-01-I

相关推荐: Samba权限许可和访问控制漏洞

Samba权限许可和访问控制漏洞 漏洞ID 1105329 漏洞类型 缓冲区溢出 发布时间 1997-09-25 更新时间 2005-05-02 CVE编号 CVE-1999-0182 CNNVD-ID CNNVD-199709-019 漏洞平台 Linux …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享