|
A local overflow exists in the Common Desktop Environment (CDE) dtmail program. dtmail fails to sanitize format string characters passed on the command line resulting in a heap overflow. With a specially crafted format string, an attacker can cause arbitrary code to be executed with the privledges of the mail group resulting in a loss of confidentiality, integrity, or availability.
|