Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1269
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1269

Description:
Buffer overflow in the parse function in parse.c in zoo 2.10 might allow local users to execute arbitrary code via long filename command line arguments, which are not properly handled during archive creation. NOTE: since this issue is local and not setuid, the set of attack scenarios is limited, although is reasonable to expect that there are some situations in which the zoo user might automatically list attacker-controlled filenames to add to the zoo archive.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25264

SAID
  Secunia Advisory: SA19254
  Secunia Advisory: SA19250

MISC

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200603-12.xml

BID
  17126


Return to the previous page.