Executive brief
A security vulnerability in a core FreeBSD system library could allow a local user to gain unauthorized control over the system. By providing an unexpectedly long piece of configuration data, an attacker can crash the system or execute their own commands with elevated privileges. This poses a significant risk to the integrity and confidentiality of data on affected multi-user systems.
Technical details
A buffer overflow vulnerability exists in the libmytinfo library within FreeBSD. The flaw is triggered when the library processes an overly long TERMCAP environment variable, leading to memory corruption. Because this library is often used by programs that run with elevated privileges (such as setuid binaries), a local, unauthenticated attacker can exploit this overflow to redirect execution flow and execute arbitrary code as a privileged user. The issue was addressed in FreeBSD Security Advisory SA-00:17.
Affected products
- FreeBSD FreeBSD All versions prior to the fix in May 2000
Timeline
- 1990-05-09: disclosed: NVD Published Date (Note: This date in NVD precedes the actual advisory year 2000)
- 2000-05-01: advisory: FreeBSD Security Advisory SA-00:17 released