Executive brief
A security vulnerability exists in xmcd, a CD player and ripper utility commonly used on older Unix-like operating systems. A local user with access to the system can exploit this flaw to gain unauthorized elevated privileges. This could allow an attacker to take full control of the affected machine, potentially leading to data theft or system disruption.
Technical details
A buffer overflow vulnerability exists in xmcd version 2.0p12. The flaw is triggered by the improper handling of environmental variables, which can be manipulated by a local attacker to overflow a buffer and execute arbitrary code. Because xmcd often runs with elevated privileges (such as setuid root) to access hardware devices, successful exploitation allows a local user to escalate their privileges to the level of the application. The vulnerability is reachable via local shell access without requiring prior authentication beyond initial system login.
Affected products
- Ti Kan xmcd 2.0p12
- Sun Microsystems Solaris 2.5.1, 7.0, 8.0
Timeline
- 1997-03-01: disclosed: Initial publication date