Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/7979 | vdb entry |
http://securitytracker.com/id?1003241 | exploit vdb entry vendor advisory |