SCO UnixWare xlock(1) (long...

- AV AC AU C I A
发布: 1999-11-25
修订: 2025-04-13

Certain versions of Unixware ship with a version of xlock which is vulnerable to a buffer overflow attack. The xlock(1) program locks the local X display until a username and password are entered. In this instance a user can provide an overly long username and overflow a buffer in xlock(1). Given that xlock(1) runs SUID root this will result in a root compromise.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息