what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

ksrt.001.svgalib.zgv

ksrt.001.svgalib.zgv
Posted Sep 23, 1999

ksrt.001.svgalib.zgv

SHA-256 | e1d9a21d43cd9f810391a7c9307bd2cdd80ef013180bd217373eb8add105a749

ksrt.001.svgalib.zgv

Change Mirror Download

PKUNZIP (R) FAST! Extract Utility Version 2.04g 02-01-93
Copr. 1989-1993 PKWARE Inc. All Rights Reserved. Registered version
PKUNZIP Reg. U.S. Pat. and Tm. Off.

þ 80486 CPU detected.
þ XMS version 3.00 detected.

Searching ZIP: LAPTOP2.ZIP
Inflating: ksrt.advisory.001 <to console>


From ksrt@DEC.NET Fri Jun 20 04:48:01 1997
Date: Thu, 19 Jun 1997 14:15:42 -0700
From: ksrt <ksrt@DEC.NET>
To: BUGTRAQ@netspace.org
Subject: svgalib/zgv

KSR[T] Advisory #001
Date: June 09, 1997
ID #: lin-svga-001

Operating System(s): Redhat Linux 3.0.3 - 4.1 / Any Linux with zgv setuid root.

Affected Program: svgalib/zgv-2.7 ( an svgalib GIF/JPG viewer )

Problem Description: svgalib 1.2.10 and below do not properly revoke
privileges, and through the use of saved user ids,
any svgalib application may still be vulnerable to
buffer overruns(stack overwrites).

zgv will take data from an environment variable (HOME),
and copies the entire length of the envirnment variable
into an automatic character buffer. The result is that
arbitrary code may be executed as root. There are also
overflows on the command line and through stdin.

Compromise: With zgv, the consequences are minimal, as only a user
who has access to the console can exploit this hole.
However, most svgalib applications are poorly written
from a security standpoint and the potential compromise
may be greater with other applications.

Patch/Fix: svgalib-1.2.11 will address this security issue. Look
for our upcoming paper on vulnerabilities in svgalib
that will explain proper programming methods and other
potential problems with svgalib applications.


---

Please note that this was not a full audit of zgv, and there may be other
security problems related to zgv.

-----
KSR[T] Website : http://www.dec.net/ksrt
E-mail: ksrt@dec.net

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close