vendor:
TerminatorX
by:
demz (geekz.nl)
7.2
CVSS
HIGH
Stack-Based Buffer Overflow
119
CWE
Product Name: TerminatorX
Affected Version From: TerminatorX v3.81
Affected Version To: TerminatorX v3.81
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Redhat 9.0
2004
TerminatorX Multiple Vulnerabilities
It has been reported that TerminatorX may be prone to multiple vulnerabilities when handling command-line and environment variable data. As a result, an attacker may be capable of exploiting the application in a variety of ways to execute arbitrary code with elevated privileges. A proof-of-concept exploit has been released which demonstrates a stack-based buffer overflow vulnerability in TerminatorX v3.81. This vulnerability is only exploitable when the application is compiled with the --enable-suidroot flag.
Mitigation:
Do not compile TerminatorX with the --enable-suidroot flag.