CVE-2006-0224

Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration file name).
References
Link Resource
http://freshmeat.net/projects/libast/?branch_id=17907&release_id=217840
http://secunia.com/advisories/18586
http://secunia.com/advisories/18632
http://secunia.com/advisories/18916
http://securityreason.com/securityalert/373
http://www.debian.org/security/2006/dsa-976
http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:029
http://www.osvdb.org/22735
http://www.rosiello.org/en/read_bugs.php?id=25 Patch Vendor Advisory
http://www.securityfocus.com/archive/1/423088/100/0/threaded
http://www.securityfocus.com/archive/1/423207/100/0/threaded
http://www.securityfocus.com/archive/1/423366/100/0/threaded
http://www.securityfocus.com/bid/16350 Exploit
http://www.vupen.com/english/advisories/2006/0314
https://exchange.xforce.ibmcloud.com/vulnerabilities/24303
http://freshmeat.net/projects/libast/?branch_id=17907&release_id=217840
http://secunia.com/advisories/18586
http://secunia.com/advisories/18632
http://secunia.com/advisories/18916
http://securityreason.com/securityalert/373
http://www.debian.org/security/2006/dsa-976
http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:029
http://www.osvdb.org/22735
http://www.rosiello.org/en/read_bugs.php?id=25 Patch Vendor Advisory
http://www.securityfocus.com/archive/1/423088/100/0/threaded
http://www.securityfocus.com/archive/1/423207/100/0/threaded
http://www.securityfocus.com/archive/1/423366/100/0/threaded
http://www.securityfocus.com/bid/16350 Exploit
http://www.vupen.com/english/advisories/2006/0314
https://exchange.xforce.ibmcloud.com/vulnerabilities/24303
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libast:libast:0.4:*:*:*:*:*:*:*
cpe:2.3:a:libast:libast:0.5:*:*:*:*:*:*:*
cpe:2.3:a:libast:libast:0.6:*:*:*:*:*:*:*
cpe:2.3:a:libast:libast:0.6.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:05

Type Values Removed Values Added
References () http://freshmeat.net/projects/libast/?branch_id=17907&release_id=217840 - () http://freshmeat.net/projects/libast/?branch_id=17907&release_id=217840 -
References () http://secunia.com/advisories/18586 - () http://secunia.com/advisories/18586 -
References () http://secunia.com/advisories/18632 - () http://secunia.com/advisories/18632 -
References () http://secunia.com/advisories/18916 - () http://secunia.com/advisories/18916 -
References () http://securityreason.com/securityalert/373 - () http://securityreason.com/securityalert/373 -
References () http://www.debian.org/security/2006/dsa-976 - () http://www.debian.org/security/2006/dsa-976 -
References () http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml - () http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:029 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:029 -
References () http://www.osvdb.org/22735 - () http://www.osvdb.org/22735 -
References () http://www.rosiello.org/en/read_bugs.php?id=25 - Patch, Vendor Advisory () http://www.rosiello.org/en/read_bugs.php?id=25 - Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/423088/100/0/threaded - () http://www.securityfocus.com/archive/1/423088/100/0/threaded -
References () http://www.securityfocus.com/archive/1/423207/100/0/threaded - () http://www.securityfocus.com/archive/1/423207/100/0/threaded -
References () http://www.securityfocus.com/archive/1/423366/100/0/threaded - () http://www.securityfocus.com/archive/1/423366/100/0/threaded -
References () http://www.securityfocus.com/bid/16350 - Exploit () http://www.securityfocus.com/bid/16350 - Exploit
References () http://www.vupen.com/english/advisories/2006/0314 - () http://www.vupen.com/english/advisories/2006/0314 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24303 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24303 -

Information

Published : 2006-01-25 02:03

Updated : 2025-04-03 01:03


NVD link : CVE-2006-0224

Mitre link : CVE-2006-0224

CVE.ORG link : CVE-2006-0224


JSON object : View

Products Affected

libast

  • libast