|
|
|
![]() |
Vulnerability Note VU#354838FTE fails to properly validate command line argumentsOverviewFTE contains a vulnerability in the processing of command line arguments that could allow an attacker to execute arbitrary code.I. DescriptionFTE is a text editor available for a variety of operating systems. There is a buffer overflow vulnerability in the way FTE performs bounds checking on command line arguments. By supplying an overly long string of characters as a command line argument, a local user could execute arbitrary code on the system with privileges of the FTE process. Typically, FTE is installed with setuid root privileges.II. ImpactA local user could execute arbitrary code with privileges of the FTE process.III. SolutionUpgradeUpgrade to the latest version of FTE as specified by your vendor.
References
This vulnerability was reported by Steve Kemp. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||