WWW-SQL Buffer Overflow Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1010544
|
|
SecurityTracker URL: http://securitytracker.com/id?1010544
|
|
CVE Reference: CAN-2004-0455
(Links to External Site)
|
Date: Jun 20 2004
|
Impact: Execution of arbitrary code via local system, User access via local system
|
Version(s): 0.5.7
|
Description: A buffer overflow vulnerability was reported in WWW-SQL. A local user can execute arbitrary code on the target system.
Debian reported that Ulf Harnhammar discovered a buffer overflow vulnerability in 'cgi.c'. A local user can create a web page and process the page with WWW-SQL to execute arbitrary code, the report said.
|
Impact: A local user can execute arbitrary code on the target system with the privileges of the web server.
|
Solution: No upstream solution was available at the time of this entry.
|
Vendor URL: www.jamesh.id.au/software/www-sql/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Sun, 20 Jun 2004 01:52:22 -0400
Subject: CVE: CAN-2004-0455
|
CVE: CAN-2004-0455
Debian reported that Ulf Härnhammar discovered a buffer overflow vulnerability in WWW-SQL.
A local user can create a web page and process the page with WWW-SQL to execute arbitrary
code, the report said.
|
|