Spider HOME Environment Variable...

- AV AC AU C I A
发布: 2003-09-16
修订: 2025-04-13

Spider has been reported prone to a heap overflow condition when handling HOME environment variables of excessive length. The issue presents itself, because a call to calloc() may allocate an insufficient buffer, under some circumstances. An attacker may lever this condition to corrupt adjacent malloc chunk headers with attacker-supplied data contained in a malicious 'HOME' environment variable. Although unconfirmed ultimately it may be possible that a local attacker may exploit this condition to execute arbitrary instructions with GID Games privileges.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息