[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] ltrace bug



On Wed, 8 Oct 2003, Abhisek Datta wrote:

> A heap based buffer overrun bug is identified in ltrace 'Library Call
> Tracer' utility version 0.3.10-12 which allows execution of arbitrarty
> code with root privilage by corrupting the heap.

I don't see any way how this bug could allow execution of code with root
privileges, as far as ltrace is not suid root.

-- 
JiKos.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html