|
VICE Monitor "Memory Dump" Command Format String Vulnerability
|
|
Secunia Advisory:
|
SA11860
|
|
|
Release Date:
|
2004-06-16
|
|
Popularity:
|
5,872 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Privilege escalation
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | VICE 1.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Spiro Trikaliotis has reported a vulnerability in VICE, which potentially can be exploited by a malicious, local users to gain escalated privileges.
The vulnerability is caused due to a format string error within the monitor "memory dump" command. This can potentially be exploited by inserting specially crafted content containing format specifiers in memory and tricking another user into entering the monitor and type the "memory dump" command.
Successful exploitation may potentially allow execution of arbitrary code with the privileges of the user invoking VICE.
The vulnerability has been reported in versions 1.6 through 1.14. Prior versions may also be affected.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|