7.2

CVE-2004-2372

Exploit
Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path.  NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bochs ProjectBochs Version < 2.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.484
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securitytracker.com/id?1009219
Patch
Third Party Advisory
VDB Entry
http://sourceforge.net/project/shownotes.php?release_id=215733
Patch
http://www.securiteam.com/unixfocus/5XP0L1FC0M.html
Patch
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/15309
VDB Entry