CVE-2000-1124
published 2001-01-09CVE-2000-1124: Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
0.89%
55.8th percentile
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Empty ROS Strings
exploitdb·2019-07-10
CVE-2019-1124 Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Empty ROS Strings
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Empty ROS Strings
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
At the time of this writing, based on the available source code, we conclude tha
Exploit-DB
IBM AIX 4.3.x - '/usr/lib/lpd/piobe' Local Buffer Overflow
exploitdb·2000-12-01
CVE-2000-1124 IBM AIX 4.3.x - '/usr/lib/lpd/piobe' Local Buffer Overflow
IBM AIX 4.3.x - '/usr/lib/lpd/piobe' Local Buffer Overflow
---
/*
source: https://www.securityfocus.com/bid/2037/info
AIX is a variant of the UNIX Operating System, distributed by IBM. A problem exists which can allow a local user elevated priviledges.
The problem exists in the piobe program. Due to the insuffient handling of the PIOSTATUSFILE, PIOTITLE, and PIOVARDIR environment variables, it's possible to overwrite stack variables. This makes it possible for a malicious user to pass specially formatted strings to the program via environment variables, and potentially gain administrative access.
*/
/*## copyright LAST STAGE OF DELIRIUM dec 2000 poland *://lsd-pl.net/ #*/
/*## /usr/lib/lpd/piobe #*/
/* note: to avoid potential system hang-up please, first obtain the exact */
/* AIX O
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=97569466809056&w=2http://www-1.ibm.com/support/search.wss?rs=0&q=IY12638&apar=onlyhttp://www.securityfocus.com/bid/2037https://exchange.xforce.ibmcloud.com/vulnerabilities/5616http://marc.info/?l=bugtraq&m=97569466809056&w=2http://www-1.ibm.com/support/search.wss?rs=0&q=IY12638&apar=onlyhttp://www.securityfocus.com/bid/2037https://exchange.xforce.ibmcloud.com/vulnerabilities/5616
2001-01-09
Published