vendor:
Chinput
by:
xperc@hotmail.com
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Chinput
Affected Version From: Chinput 3.0
Affected Version To: Chinput 3.0
Patch Exists: NO
Related CWE: N/A
CPE: a:chinput:chinput:3.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: TurboLinux 6.5 with kernel 2.2.18
2002
Chinput Local Buffer Overflow Vulnerability
A vulnerability exists in Chinput. A local user with an extremely long HOME environment variable may cause a buffer to overflow. If successfully exploited, this can overwrite the instruction pointer, and lead to the execution of arbitrary code as root.
Mitigation:
The user should ensure that the HOME environment variable is not set to an excessively long value.