4.6
CVSSv2

CVE-2000-0976

Published: 19/12/2000 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

xfree86 project xlib 3.3x

Exploits

source: wwwsecurityfocuscom/bid/1805/info A vulnerability exists in xlib, the C language interface to the X Window System protocol When applications linked to the xlib library are run, user-supplied values for the DISPLAY environment variable (and the command-line argument -display) are stored in buffers of predefined length It is not ...