|
A local overflow exists in Orville Write. The "amin" binary fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request to the environment variable, a malicious user can cause arbitrary code execution with elevated privileges, possibly root, if the program was installed setuid, or "tty" group privileges, if the program was installed setgid, resulting in a loss of integrity.
|