Multiple off-by-one errors in opiesu.c in opiesu in OPIE 2.4.1-test1 and earlier might allow local users to gain privileges via a crafted command line.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2011/06/23/5 | patch mailing list exploit |
http://www.openwall.com/lists/oss-security/2011/06/22/6 | patch mailing list exploit |
https://hermes.opensuse.org/messages/10082052 | vendor advisory |
https://bugzilla.novell.com/show_bug.cgi?id=698772 | patch exploit |
https://bugzillafiles.novell.org/attachment.cgi?id=435902 | patch |
http://www.debian.org/security/2011/dsa-2281 | vendor advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631344 | patch |
https://hermes.opensuse.org/messages/10082068 | vendor advisory |
http://www.securityfocus.com/bid/48390 | vdb entry |
http://secunia.com/advisories/45448 | third party advisory |
http://secunia.com/advisories/45136 | third party advisory vendor advisory |