Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-4581

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2005-4581
Last Modified 07 Mar 2011 09:28:32
Published 29 Dec 2005 06:03:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2005-4581

Summary

Buffer overflow in Electric Sheep 2.6.3 client allows local users to execute arbitrary code via a long window-id parameter. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.

Vulnerable Systems

Application

  • Scott Draves Electric Sheep 2.6.3


References

BUGTRAQ - 20051223 Electric Sheep window-id stack overflow

MISC - http://electricsheep.org/release_notes.html

CONFIRM - http://electricsheep.org/index.cgi?&menu=talk

CONFIRM - http://draves.org/HyperNews/get.cgi/flame/1478/1.html

CONFIRM - http://draves.org/HyperNews/get.cgi/flame/1478.html

XF - electric-sheep-windowid-bo(23893)


Last Updated: 27 May 2016 10:41:22