7.2
CVSSv2

CVE-1999-0137

Published: 09/07/1996 Updated: 17/08/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 730
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The dip program on many Linux systems allows local users to gain root access via a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

fred n. van kempen dip 3.3.7o

Exploits

source: wwwsecurityfocuscom/bid/86/info A buffer overflow resides in 'dip-337o' and derived programs This is a problem only on systems where 'dip' is installed setuid The culpable code is an 'sprintf()' in line 192 in 'mainc': sprintf(buf, "%s/LCK%s", _PATH_LOCKD, nam); /* Linux x86 dip 337p exploit by pr10n */ #include < ...
source: wwwsecurityfocuscom/bid/86/info A buffer overflow resides in 'dip-337o' and derived programs This is a problem only on systems where 'dip' is installed setuid The culpable code is an 'sprintf()' in line 192 in 'mainc': sprintf(buf, "%s/LCK%s", _PATH_LOCKD, nam); ----- dip-expc ----- /* dip 337o buffer overflow explo ...