sharutils: arbitrary code execution
Package(s): | sharutils |
CVE #(s): | CAN-2004-1772
|
Created: | October 1, 2004 |
Updated: | April 26, 2005 |
Description: |
sharutils contains two buffer overflows. Ulf Harnhammar discovered a buffer
overflow in shar.c, where the length of data returned by the wc command is
not checked. Florian Schilhabel discovered another buffer overflow in
unshar.c. An attacker could exploit these vulnerabilities to execute
arbitrary code as the user running one of the sharutils programs. |
Alerts: |
|