innfeed Command-Line Buffer Overflow...

- AV AC AU C I A
发布: 2001-04-18
修订: 2025-04-13

The innfeed utility, part of ISC InterNetNews, has an exploitable buffer overflow in its command-line parser. Specifically, innfeed will overflow if an overly long -c option is passed to it. A local attacker in the news group could use this overflow to execute arbitary code with an effective userid of news, which could constitute an elevation in privileges, and the ability to alter news-owned binaries that could be run by root. Exploits are available against x86 Linux builds of innfeed.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息