OSVDB ID: 8333

Title: Conquest Environment Variable Overflow

Info

Disclosure

Mar 16, 1998

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A local overflow exists in Conquest. In conf.c and conqlb.c there are several sprintf calls that read data from the HOME variable without checking the length resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code as the group that owns the conquest executable (conquest is installed SGID) resulting in a loss of integrity, and/or availability.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 8.0 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): apply the patch from the Debian project to 7.1.

Products

RADSCAN

Conquest

5.8
6.0
6.3
6.4
6.6
7.0
7.0.1
7.1
7.1.1
7.1.2
7.2
7.1.1-6woody1

References

Credit

  • Steve Kemp -
  • Bst - bstBrand New Doo Dooiname.com -


Direct URL: http://osvdb.org/36218