QNX Photon MicroGUI多个效用服务器标记缓冲区溢出漏洞

QNX Photon MicroGUI多个效用服务器标记缓冲区溢出漏洞

漏洞ID 1108165 漏洞类型 缓冲区溢出
发布时间 2004-09-13 更新时间 2005-10-20
图片[1]-QNX Photon MicroGUI多个效用服务器标记缓冲区溢出漏洞-安全小百科CVE编号 CVE-2004-1681
图片[2]-QNX Photon MicroGUI多个效用服务器标记缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200408-222
漏洞平台 Unix CVSS评分 7.2
|漏洞来源
https://www.exploit-db.com/exploits/24596
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200408-222
|漏洞详情
QNXRTP6.1版本的QNXPhotonmicroGUI的(1)phrelay-cfg,(2)phlocale,(3)pkg-installer或者(4)input-cfg存在多个缓冲区溢出漏洞。本地用户借助超长-s(服务器)命令行参数提升特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/11164/info
  
Reportedly QNX Photon MicroGUI is affected by multiple buffer overflow vulnerabilities in MicroGUI utilities. These issues are due to a failure of the affected applications to validate user-supplied string lengths before copying them into finite process buffers.
  
An attacker may leverage these issues to execute arbitrary code on the affected system within the context of the vulnerable applications; the applications are typically setuid applications.

$ /usr/photon/bin/pkg-installer -s AAAAA[...]
|参考资料

来源:XF
名称:qnx-rtp-photon-bo(17339)
链接:http://xforce.iss.net/xforce/xfdb/17339
来源:BID
名称:11164
链接:http://www.securityfocus.com/bid/11164
来源:www.rfdslabs.com.br
链接:http://www.rfdslabs.com.br/qnx-advs-03-2004.txt
来源:BUGTRAQ
名称:20040913[RLSA_02-2004]QNXPhotonmultiplebufferoverflows
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109510393407597&w;=2

相关推荐: Microsoft JET Database Engine VBA Vulnerability

Microsoft JET Database Engine VBA Vulnerability 漏洞ID 1104787 漏洞类型 Input Validation Error 发布时间 1999-05-25 更新时间 1999-05-25 CVE编号 N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享