Multiple Linux vendor imwheel...

- AV AC AU C I A
发布: 2000-03-13
修订: 2025-04-13

A vulnerability exists in the 'imwheel' package for Linux. This package is known to be vulnerable to a buffer overrun in its handling of the HOME environment variable. By supplying a sufficiently long string containing machine executable code, the imwheel program can be caused to run arbitrary commands as root. This is due to a setuid root perl script named 'imwheel-solo' which invokes the imwheel program with effective UID 0.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息