CVE-2000-1119
published 2001-01-09CVE-2000-1119: Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
PriorityP417medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EXPLOIT
EPSS
0.98%
58.5th percentile
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Incorrect Handling of blendArray
exploitdb·2019-07-10
CVE-2019-1119 Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Incorrect Handling of blendArray
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Incorrect Handling of blendArray
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
At the time of this writing, based on the available source code, we conclude that AF
Exploit-DB
IBM AIX 4.x - '/usr/bin/setsenv' Local Buffer Overflow
exploitdb·2000-12-01
CVE-2000-1119 IBM AIX 4.x - '/usr/bin/setsenv' Local Buffer Overflow
IBM AIX 4.x - '/usr/bin/setsenv' Local Buffer Overflow
---
/*
source: https://www.securityfocus.com/bid/2032/info
AIX is a version of the UNIX Operating System distributed by IBM. A problem exists that could allow a user elevated priviledges.
The problem occurs in the setsenv binary. It has been reported that a buffer overflow exists in this binary which could allow a user to overwrite variables on the stack, including the return address. This makes it possible for a malicious user to execute arbitrary code, and potentially attain a UID of 0.
*/
/*## copyright LAST STAGE OF DELIRIUM sep 2000 poland *://lsd-pl.net/ #*/
/*## /usr/bin/setsenv #*/
/* note: to avoid potential system hang-up please, first obtain the exact */
/* AIX OS level with the use of the uname -a or oslevel commands
Exploit-DB
Concatus IMate Web Mail Server 2.5 - Remote Buffer Overflow
exploitdb·2000-06-01
CVE-2000-0507 Concatus IMate Web Mail Server 2.5 - Remote Buffer Overflow
Concatus IMate Web Mail Server 2.5 - Remote Buffer Overflow
---
source: https://www.securityfocus.com/bid/1286/info
Sending an email to a Concatus IMate Web Mail Server 2.5 with a server name consisting of over 1119 characters will cause the application to crash. Restarting the program is required in order to regain normal functionality.
Telnet target 25
HELO
Exploit-DB
Panda Security 3.0 - Multiple Vulnerabilities
exploitdb·2000-04-17
CVE-2000-0264 Panda Security 3.0 - Multiple Vulnerabilities
Panda Security 3.0 - Multiple Vulnerabilities
---
source: https://www.securityfocus.com/bid/1119/info
Panda Security is a user management application for Windows 9x. With it, certain functions can be prohibited for specific users.
One of the restrictive policies possible is to disable registry editing. However, even with this feature activated, any user can edit the registry by either executing a *.reg file or renaming and then executing regedit.exe. As the restriction settings for Panda are stored in the registry, this weakness negates the effectiveness of the rest of the Panda software.
In addition, users can uninstall Panda Security through the Add/Remove Programs applet in the Control Panel. An error message will appear when the user attempts to uninstall Panda Security. However u
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=97569466809056&w=2http://www-1.ibm.com/support/search.wss?rs=0&q=IY08812&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY10721&apar=onlyhttp://www.osvdb.org/1676http://www.securityfocus.com/bid/2032https://exchange.xforce.ibmcloud.com/vulnerabilities/5621http://marc.info/?l=bugtraq&m=97569466809056&w=2http://www-1.ibm.com/support/search.wss?rs=0&q=IY08812&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY10721&apar=onlyhttp://www.osvdb.org/1676http://www.securityfocus.com/bid/2032https://exchange.xforce.ibmcloud.com/vulnerabilities/5621
2001-01-09
Published