Vulnerabilities
Vulnerable Software
Osh:  >> Osh  >> 1.7.14  Security Vulnerabilities
Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.
CVSS Score
7.2
EPSS Score
0.002
Published
2005-11-20


Contact Us

Shodan ® - All rights reserved