Executive brief
A vulnerability in the xmcd CD player utility allows local users to gain elevated system privileges. By exploiting a flaw in how the application handles user-defined resource settings, an attacker who already has access to a machine can take full control of the system. This could lead to unauthorized access to sensitive data or the disruption of system operations.
Technical details
A buffer overflow vulnerability exists in xmcd version 2.1. The flaw is triggered when the application processes specific user resource settings, which fails to properly validate the length of input data before copying it into a fixed-size buffer. Because xmcd often runs with elevated privileges (such as setuid root) to access hardware devices, a local attacker can exploit this overflow to execute arbitrary code with the privileges of the application. This results in a complete compromise of confidentiality, integrity, and availability on the local host.
Affected products
- xmcd project xmcd 2.1
Timeline
- 1996-10-01: disclosed: Initial publication date in NVD