Vulnerabilities > CVE-2002-1506 - Local Environment Variable Buffer Overflow vulnerability in Linuxconf

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
jacques-gelinas
exploit available

Summary

Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.

Exploit-Db

  • descriptionLinuxconf 1.1.x/1.2.x Local Environment Variable Buffer Overflow Vulnerability (2). CVE-2002-1506. Local exploit for linux platform
    idEDB-ID:21762
    last seen2016-02-02
    modified2002-08-28
    published2002-08-28
    reporterDavid Endler
    sourcehttps://www.exploit-db.com/download/21762/
    titleLinuxconf 1.1.x / 1.2.x - Local Environment Variable Buffer Overflow Vulnerability 2
  • descriptionLinuxconf 1.1.x/1.2.x Local Environment Variable Buffer Overflow Vulnerability (1). CVE-2002-1506. Local exploit for linux platform
    idEDB-ID:21761
    last seen2016-02-02
    modified2002-08-28
    published2002-08-28
    reporterRaiSe
    sourcehttps://www.exploit-db.com/download/21761/
    titleLinuxconf 1.1.x / 1.2.x - Local Environment Variable Buffer Overflow Vulnerability 1
  • descriptionLinuxconf 1.1.x/1.2.x Local Environment Variable Buffer Overflow Vulnerability (3). CVE-2002-1506. Local exploit for linux platform
    idEDB-ID:21763
    last seen2016-02-02
    modified2002-08-28
    published2002-08-28
    reportersyscalls
    sourcehttps://www.exploit-db.com/download/21763/
    titleLinuxconf 1.1.x / 1.2.x - Local Environment Variable Buffer Overflow Vulnerability 3