Vulnerabilities > CVE-2002-1476 - Unspecified vulnerability in Netbsd
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the boundaries of the new_categories category array, as exploitable through programs such as xterm and zsh.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 6 |
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-012.txt.asc
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-012.txt.asc
- http://www.iss.net/security_center/static/10159.php
- http://www.iss.net/security_center/static/10159.php
- http://www.osvdb.org/7565
- http://www.osvdb.org/7565
- http://www.securityfocus.com/bid/5724
- http://www.securityfocus.com/bid/5724