vendor:
xlockmore
by:
Ben Williams
7.5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: xlockmore
Affected Version From: All versions of xlock derived from xlockmore
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2000-0866
CPE: a:xlock:xlockmore
Platforms Tested: Linux (specifically tested on Slackware 7.1, Redhat 6.2, and Mandrake 7.0)
2000
Xlockmore Program Format String Vulnerability
The xlockmore program is vulnerable to a format string vulnerability that can be exploited to execute arbitrary code with root privileges. By supplying format strings in the display value (-d option), an attacker can overwrite values on the stack and gain control of the program. This vulnerability affects all versions of xlock derived from xlockmore, including the version shipped with various operating systems.
Mitigation:
Apply the vendor's patch or update to a non-vulnerable version of xlockmore.