|
|
>> MotifZone OpenMotif "libUil" Multiple Buffer Overflow Vulnerabilities
|
Title : MotifZone OpenMotif "libUil" Multiple Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2005-2709 CVE ID : CVE-2005-3964
Rated as : High Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-03
|
Multiple vulnerabilities were identified in OpenMotif, which could be exploited by attackers to cause a denial of service or execute arbitrary commands. These flaws are due to buffer overflow errors in the "diag_issue_diagnostic()" [Clients/uil/UilDiags.c] and "open_source_file()" [Clients/uil/UilSrcSrc.c] functions when processing specially crafted data, which could be exploited by attackers to execute arbitrary code or crash an application linked against the vulnerable library.
Affected Products
MotifZone OpenMotif version 2.2.3 and prior
Solution
VUPEN Security is not aware of any vendor-supplied patch.
References
http://www.vupen.com/english/advisories/2005/2709 http://www.frsirt.com/english/reference/1864
Credits
Vulnerabilities reported by xfocus
ChangeLog
2005-12-03 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|