vendor:
phlocale
by:
badc0ded.com
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: phlocale
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
QNX phlocale $ABLANG exploit
The QNX phlocale utility is prone to an exploitable buffer overflow condition due to insufficient bounds checking of the ABLANG environment variable. Exploitation of this issue may result in execution of arbitrary attacker-supplied instructions as root.
Mitigation:
Ensure that the ABLANG environment variable is properly sanitized and bounds checked.