A local overflow exists in some versions of the at(1) program. The program fails to validate input properly resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code as root resulting in a loss of integrity and confidentiality.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored
Disclosure:
OSVDB Verified
Solution
Consult the vendor for the appropriate patch. It is also possible to correct the flaw by implementing the following workaround: Remove the permissions of the at(1) program.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.