CVE
- Id
- 1595
- CVE No.
- CVE-2000-0017
- Status
- Candidate
- Description
- Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.
- Phase
- Proposed (20000111)
- Votes
- NOOP(4) Armstrong, Baker, Christey, Stracener | REJECT(2) Frech, Levy
- Comments
- Christey> It"s not certain whether this is exploitable or not. An | expert (the linuxconf author?) wasn"t able to duplicate the | bug - see http://lwn.net/1999/1223/a/linuxconfresponse.html | | The original posting with example exploit was | http://marc.theaimsgroup.com/?l=bugtraq&m=94580196627059&w=2 | | However - GIAC and the Security Focus incidents list have | consistently reported that scans are taking place for | linuxconf, so do the hackers know more than we do? | Frech> Unless vendor or other confirmation occurs, there has been no corroboration | of this issue in public forums. | CHANGE> [Armstrong changed vote from ACCEPT to NOOP]