htop 0.7 writes process names to a terminal without sanitizing non-printable characters, which might allow local users to hide processes, modify arbitrary files, or have unspecified other impact via a process name with "crazy control strings."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2008/11/14/3 | mailing list |
http://bugs.debian.org/504144 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46321 | vdb entry |
http://www.openwall.com/lists/oss-security/2008/11/02/1 | mailing list |
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html | vendor advisory |
http://www.securityfocus.com/bid/32081 | vdb entry |