Vulnerabilities > CVE-2004-2372 - Unspecified vulnerability in Bochs Project Bochs
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path. NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.
Vulnerable Configurations
References
- http://securitytracker.com/id?1009219
- http://securitytracker.com/id?1009219
- http://sourceforge.net/project/shownotes.php?release_id=215733
- http://sourceforge.net/project/shownotes.php?release_id=215733
- http://www.securiteam.com/unixfocus/5XP0L1FC0M.html
- http://www.securiteam.com/unixfocus/5XP0L1FC0M.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15309
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15309