WMCube/GDK Object File Buffer...

- AV AC AU C I A
发布: 2001-12-17
修订: 2025-04-13

WMCube/GDK is a freely available, open source application for monitoring CPU load. It can be used with one, or multiple CPU's. WMCube/GDK does not properly impose the limit of 64 byte object files hard-coded into the program. Because of this, it is possible for a local user to load an object file greater than 64 bytes, creating a buffer overflow. This overflow could be used to overwrite stack variables, including the return address, and execute arbitrary code. A local attacker may gain egid 'kmem', which allows for reading of kernel memory. Elevation to root is imminent when attackers can read kmem.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息