CVE-2012-3368
Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by…
Does this matter?
Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.
Description
Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- redhat/dtach
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=625302
- http://sourceforge.net/tracker/?func=detail&aid=3517812&group_id=36489&atid=417357Exploit
- http://sourceforge.net/tracker/download.php?group_id=36489&atid=417357&file_id=441195&aid=3517812Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=812551Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=835849
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=625302
- http://sourceforge.net/tracker/?func=detail&aid=3517812&group_id=36489&atid=417357Exploit
- http://sourceforge.net/tracker/download.php?group_id=36489&atid=417357&file_id=441195&aid=3517812Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=812551Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=835849
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.