Vulnerability Name: | CVE-2002-1476 (CCN-10159) | ||||||||
Assigned: | 2002-09-17 | ||||||||
Published: | 2002-09-17 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the boundaries of the new_categories category array, as exploitable through programs such as xterm and zsh. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: NETBSD Type: UNKNOWN NetBSD-SA2002-012 Source: CCN Type: Full-Disclosure Mailing List, Mon Sep 16 2002 - 21:27:09 CDT buffer overrun in setlocale Source: MITRE Type: CNA CVE-2002-1476 Source: XF Type: Patch, Vendor Advisory netbsd-libc-setlocale-bo(10159) Source: OSVDB Type: UNKNOWN 7565 Source: CCN Type: OSVDB ID: 7565 NetBSD libc setlocale LC_ALL Category Privilege Escalation Source: BID Type: Patch, Vendor Advisory 5724 Source: CCN Type: BID-5724 NetBSD LibC SetLocale Buffer Overflow Vulnerability Source: XF Type: UNKNOWN netbsd-libc-setlocale-bo(10159) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |