[40244] in bugtraq

home help back first fref pref prev next nref lref last post

KillProcess 2.20 and priors "FileDescription" Local Buffer

daemon@ATHENA.MIT.EDU (fRoGGz@securityfocus.com)
Fri Sep 9 15:53:38 2005

Date: 9 Sep 2005 16:18:12 -0000
Message-ID: <20050909161812.22460.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: fRoGGz@securityfocus.com
To: bugtraq@securityfocus.com

I'm really sorry, but there is a big mistake !
Last ANALYSIS paragraph is false !
Please, correct by this.

"ANALYSIS
--------
Exploitation of the described vulnerability allows attackers to
execute arbitrary code under the context of the user who started KillProcess."



home help back first fref pref prev next nref lref last post