Summary: | IBM AIX and possibly other Unix variants are vulnerable to a buffer overflow in the CDE DtSvc library. By sending a specially-crafted string to the dtprintinfo or dtterm command using the "-session" option, a local attacker can overflow a buffer in DtSvc and execute arbitrary code on the system to gain root privileges. |