LWN.net Logo

calife: buffer overflow

Package(s):calife CVE #(s):CAN-2004-0188
Created:March 17, 2004 Updated:March 17, 2004
Description: Calife, a program which provides super user privileges to specific users, was found to contain a buffer overflow related to the getpass(3) library function. A local attacker could potentially exploit this vulnerability, given knowledge of a local user's password and the presence of at least one entry in /etc/calife.auth, to execute arbitrary code with root privileges.
Alerts:
Debian DSA-461-1 2004-03-11

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds