vendor:
XFree86 Utilities
by:
Angelo Rosiello & deka
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: XFree86 Utilities
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
XFree86 Utilities Buffer Overflow Vulnerability
Several XFree86 utilities may be prone to a buffer overflow condition. The vulnerability exists due to insufficient boundary checks performed by these utilities when referencing the XLOCALEDIR environment variable. A local attacker can exploit this vulnerability by setting the XLOCALEDIR environment variable to an overly long value. When the vulnerable utilities are executed, the buffer overflow vulnerability will be triggered.
Mitigation:
Ensure that the XLOCALEDIR environment variable is set to a valid value and is not overly long.