Buffer overflow in the daemon function in midirecord.cc in Tuomas Airaksinen Midirecord 2.0 allows local users to execute arbitrary code via a long command line argument (filename). NOTE: This may not be a vulnerability if Midirecord is not installed setuid.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/441204/100/0/threaded | mailing list |
http://securityreason.com/securityalert/1303 | third party advisory |
http://www.securityfocus.com/bid/19190 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28047 | vdb entry |
http://advisories.echo.or.id/adv/adv41-theday-2006.txt | exploit vendor advisory |