vendor:
xklock
by:
dethy
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: xklock
Affected Version From: FreeBSD 3.5.1
Affected Version To: FreeBSD 4.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: FreeBSD
2001
xklock – FreeBSD 3.5.1 & 4.2 ports package local root exploit
The xklock program in FreeBSD 3.5.1 and 4.2 ports package contains several exploitable buffer overflows in command line arguments as well as the 'JNAME' environment variable. This exploit abuses the -bg argument.
Mitigation:
Update to a patched version of xklock or remove the setuid root permission from the program.