vendor:
xmindpath
by:
Brock Tellier
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: xmindpath
Affected Version From: 3.3
Affected Version To: 3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:freebsd:freebsd:3.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD
2000
FreeBSD 3.3 xmindpath exploit gives euid uucp
The version of xmindpath shipped with FreeBSD 3.3 can be locally exploited via overrunning a buffer of predefined length. It is possible to gain the effective userid of uucp through this vulnerability. It may be possible, after attaining uucp priviliges, to modify binaries to which uucp has write access to and trojan them to further elevate priviliges.
Mitigation:
Upgrade to the latest version of xmindpath.