FreeBSD xmindpath Buffer Overflow...

- AV AC AU C I A
发布: 1999-12-01
修订: 2025-04-13

The version of xmindpath shipped with FreeBSD 3.3 can be locally exploited via overrunning a buffer of predefined length. It is possible to gain the effective userid of uucp through this vulnerability. It may be possible, after attaining uucp priviliges, to modify binaries to which uucp has write access to and trojan them to further elevate priviliges), ie: modify minicom so that when root runs it, drops a suid shell somewhere.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息