CVE-2002-0184 – Sudo 1.6.x - Password Prompt Heap Overflow
https://notcve.org/view.php?id=CVE-2002-0184
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded. Desbordamiento del montón (heap) en sudo anteriores a 1.6.6 puede permitir a usuarios locales ganar privilegios de root mediante caractéres especiales en el argumento -p (prompt), que no son expandidos adecuadamente. • https://www.exploit-db.com/exploits/21420 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000475 http://marc.info/?l=bugtraq&m=101974610509912&w=2 http://marc.info/?l=bugtraq&m=101975443619600&w=2 http://marc.info/?l=bugtraq&m=101979472822196&w=2 http://marc.info/? • CWE-131: Incorrect Calculation of Buffer Size •
CVE-2002-0062
https://notcve.org/view.php?id=CVE-2002-0062
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling." El desbordamiento del búfer en ncurses 5.0, y el paquete de compatibilidad ncurses4 basado en él, permite a usuarios locales la obtención de privilegios. • http://www.debian.org/security/2002/dsa-113 http://www.iss.net/security_center/static/8222.php http://www.redhat.com/support/errata/RHSA-2002-020.html http://www.securityfocus.com/bid/2116 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2002-0004 – AT 3.1.8 - Formatted Time Heap Overflow
https://notcve.org/view.php?id=CVE-2002-0004
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice. Corrupción de memoria en el comando "at" permite que usuarios locales ejecuten código arbitrario haciendo uso de un tiempo de ejecución mal escrito (lo que provoca que at libere la misma memoria dos veces). • https://www.exploit-db.com/exploits/21229 http://marc.info/?l=bugtraq&m=101128661602088&w=2 http://marc.info/?l=bugtraq&m=101147632721031&w=2 http://online.securityfocus.com/advisories/3833 http://online.securityfocus.com/advisories/3969 http://www.debian.org/security/2002/dsa-102 http://www.novell.com/linux/security/advisories/2002_003_at_txt.html http://www.redhat.com/support/errata/RHSA-2002-015.html http://www.securityfocus.com/bid/3886 https://exchange.xforce. •
CVE-2002-0044
https://notcve.org/view.php?id=CVE-2002-0044
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files. Enscript 1.5.1 y anteriores permiten a usaurios locales sobreescribir ficheros arbitrarios del usuario Enscript mediante un ataque de enlaces simbólicos (symlink attack) en ficheros temporales. • http://www.debian.org/security/2002/dsa-105 http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-010.php3 http://www.redhat.com/support/errata/RHSA-2002-012.html http://www.securityfocus.com/advisories/3818 http://www.securityfocus.com/bid/3920 https://exchange.xforce.ibmcloud.com/vulnerabilities/7932 •
CVE-2001-1561 – Xvt 2.1 - Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-1561
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments. • https://www.exploit-db.com/exploits/20986 http://archives.neohapsis.com/archives/bugtraq/2001-07/0024.html http://www.debian.org/security/2001/dsa-082 http://www.iss.net/security_center/static/6781.php http://www.securityfocus.com/bid/2955 http://www.securityfocus.com/bid/2964 •