7.2
CVSSv2

CVE-2003-0034

Published: 07/02/2003 Updated: 11/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.

Vulnerable Product Search on Vulmon Subscribe to Product

jean-jacques sarton mtink 0.9.32

jean-jacques sarton mtink 0.9.33

jean-jacques sarton mtink 0.9.52

Exploits

source: wwwsecurityfocuscom/bid/6656/info mtink is prone to a locally exploitable buffer overflow condition This is due to insufficient bounds checking of the HOME environment variable mtink is reportedly installed setgid 'sys' on Mandrake Linux, so it is possible that this issue may be exploited to execute arbitrary code with elevated ...