Stack-based buffer overflow in the vgasco_printf function in Jan Kybic BitMap Viewer (BMV) 1.2, when compiled with the M_UNIX flag and running setuid, allows local users to gain privileges via a long filename in the -b command line option.
Link | Tags |
---|---|
http://felinemenace.org/advisories/bmv_advisory.txt | vendor advisory |