4.6
CVSSv2

CVE-2002-1476

Published: 22/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in setlocale in libc on NetBSD 1.4.x up to and including 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local malicious users to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the boundaries of the new_categories category array, as exploitable through programs such as xterm and zsh.

Vulnerable Product Search on Vulmon Subscribe to Product

netbsd netbsd 1.5

netbsd netbsd 1.5.1

netbsd netbsd 1.5.2

netbsd netbsd 1.5.3

netbsd netbsd 1.6

netbsd netbsd 1.4