Bugtraq mailing list archives

Re: Atari800 - local root. (fwd)


From: Petr Stehlik <pstehlik () sophics cz>
Date: Fri, 26 Nov 2004 11:00:35 +0100

Name:                       Atari800
Vendor URL:                 http://atari800.sourceforge.net/
Author:                     Adam Zabrocki <pi3ki31ny () wp pl>
Date:                       November 20, 2004

  Atari800 - free and portable Atari800/XL/XE/5200 emulator allows attacker to execute
shellcode with privileges suid root, where Atari800 is installed.

applies to SVGALIB target only which is deprecated and should no longer
be used. Normal binaries (curses, framebuffer, X11 and all others) are
not suid root.

This bug exist in older Atari800 (i read source with version 1.3.0), in the lasted version
there isn't overflow in Aprint() function. It was rewrited!

yes, it was, because I were notified about this problem a year ago (see
below).

Btw. Atari 1.3.3 and 1.3.2 are not vuln but i don't found any raport of this bug what i writed here.

see the DOC/ChangeLog:

2003-11-13  Petr Stehlik  <pstehlik () sophics cz>
* log.c: corrected buffer overflow found by Laios Mircea

I think it was found by Debian security team but I might be wrong (it's
more than year ago so I don't remember details).

Best regards Adam Zabrocki (pi3).

thanks for the analysis. I'll fix the other problem (in the config file
parsing).

Petr



Current thread: