Vulnerability Note VU#900964
FTE fails to properly validate environment variables
Overview
FTE contains a vulnerability in the processing of certain environment variables that could allow an attacker to execute arbitrary code.
Description
FTE is a text editor available for a variety of operating systems. There is a buffer overflow vulnerability in the way FTE performs bounds checking on certain environment variables. By supplying an overly long string of characters for the HOME or TERM environment variable, a local user could execute arbitrary code on the system with privileges of the FTE process. Typically, FTE is installed with setuid root privileges. |
Impact
A local user could execute arbitrary code with privileges of the FTE process. |
Solution
Upgrade Upgrade to the latest version of FTE as specified by your vendor. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Debian | Affected | - | 16 Apr 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://shellcode.org/Advisories/FTE.txt
- http://fte.sourceforge.net/
- http://secunia.com/advisories/11290/
- http://xforce.iss.net/xforce/xfdb/15726
- http://www.securityfocus.com/bid/10041
- http://www.debian.org/security/2004/dsa-472
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203871
Credit
This vulnerability was reported by Steve Kemp.
This document was written by Damon Morda.
Other Information
- CVE IDs: CAN-2003-0648
- Date Public: 03 Apr 2004
- Date First Published: 16 Apr 2004
- Date Last Updated: 16 Apr 2004
- Severity Metric: 10.69
- Document Revision: 3
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.