Executive brief
A security vulnerability exists in the xlock utility on HP systems, which is a program used to lock a user's display terminal. An attacker with local access to the system could exploit this flaw to bypass security restrictions and potentially gain full control over the computer. This could lead to the unauthorized access of sensitive data or a complete disruption of system operations.
Technical details
A buffer overflow vulnerability exists in the HP xlock utility. The flaw is rooted in insufficient bounds checking when handling input, which can be triggered by a local attacker. By providing specially crafted input to the xlock program, an attacker can overflow a memory buffer to execute arbitrary code with the privileges of the xlock process, which typically runs with elevated (setuid root) permissions. This allows for a complete compromise of the local system's confidentiality, integrity, and availability.
Affected products
- HP xlock
Timeline
- 1997-11-04: disclosed