7.2
CVSSv2

CVE-2015-2831

Published: 14/04/2015 Updated: 03/12/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in das_watchdog 0.9.0 allows local users to execute arbitrary code with root privileges via a large string in the XAUTHORITY environment variable.

Vulnerable Product Search on Vulmon Subscribe to Product

das watchdog project das watchdog 0.9.0

Vendor Advisories

Debian Bug report logs - #781806 das-watchdog: CVE-2015-2831: Buffer overflow in the handling of the XAUTHORITY env variable Package: das-watchdog; Maintainer for das-watchdog is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Source for das-watchdog is src:das-watchdog (PTS, buildd, popcon) ...
Adam Sampson discovered a buffer overflow in the handling of the XAUTHORITY environment variable in das-watchdog, a watchdog daemon to ensure a realtime process won't hang the machine A local user can exploit this flaw to escalate his privileges and execute arbitrary code as root For the stable distribution (wheezy), this problem has been fixed i ...