First published: Tue Dec 31 2002(Updated: )
Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gnu Data Display Debugger | =3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2099 has a moderate severity rating due to the potential for local users to execute arbitrary code.
To fix CVE-2002-2099, ensure that the version of GNU DataDisplay Debugger used is updated to a version that does not have this vulnerability.
CVE-2002-2099 affects local users of GNU Data Display Debugger version 3.3.1.
CVE-2002-2099 cannot be exploited remotely as it requires local access to the vulnerable system.
If you cannot update GNU Data Display Debugger, consider restricting user access to the system to mitigate the impact of CVE-2002-2099.