vendor:
Linux
by:
bladi & aLmUDeNa
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Linux
Affected Version From: S.u.S.E. Linux 6.3
Affected Version To: S.u.S.E. Linux 6.3
Patch Exists: NO
Related CWE:
CPE: o:suse:linux:6.3
Platforms Tested: Linux
Unknown
Vulnerability in Gnomelib handling of DISPLAY variable
By supplying a long buffer containing machine executable code in the DISPLAY environment variable, it is possible to execute arbitrary code with the permissions of the user running the binary. In the case of a setuid binary, it is possible to obtain the privileges of the user it is setuid to. This can lead to privilege escalation and potential local root compromise.
Mitigation:
Apply patches or updates to fix the vulnerability. Avoid setting the DISPLAY environment variable to arbitrary or untrusted values.