Family: Debian Local Security Checks --> Category: infos
[DSA062] DSA-062-1 rxvt Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
Samuel Dralet reported on bugtraq that version 2.6.2 of rxvt (a
VT102 terminal emulator for X) have a buffer overflow in the
tt_printf() function. A local user could abuse this making rxvt
print a special string using that function, for example by using
the -T or -name command-line options.
That string would cause a
stack overflow and contain code which rxvt will execute.
Since rxvt is installed sgid utmp a possible hacker could use this
to gain utmp which would allow them to modify the utmp file.
This has been fixed in version 2.6.2-2.1, and we recommend that
you upgrade your rxvt package.
Solution : http://www.debian.org/security/2001/dsa-062
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.