|
|
|
![]() |
Vulnerability Note VU#451275Curses library vulnerable to buffer overflowOverviewThe curses library derived from System V contains a buffer overflow. A local user can execute a command that uses this library to exploit the vulnerability and gain elevated privileges.I. DescriptionThere is a buffer overflow in the curses library that could permit a local user to gain elevated privileges. Various commands will call on the libcurses library to get the term settings either from the environment variable TERM, or a command line argument.II. ImpactA local user can gain elevated privileges.III. SolutionApply the appropriate patch from your vendor. See our "Systems Affected" section below.Systems Affected
ReferencesVU#138523 VU#126025 This vulnerability was discovered by Kevin Finisterre <dotslash@snosoft.com> and was reported to the vuln-dev@securityfocus.com mailing list. Caldera/SCO has also released an advisory (CSSA-2001-SCO.1). This document was written by Jason Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||