<<< Date Index >>>     <<< Thread Index >>>

Re: Atari800 - local root. (fwd)



> Name:                       Atari800
> Vendor URL:                 http://atari800.sourceforge.net/
> Author:                     Adam Zabrocki <pi3ki31ny@xxxxx>
> Date:                       November 20, 2004

>   Atari800 - free and portable Atari800/XL/XE/5200 emulator allows attacker 
> to execute
> shellcode with privileges suid root, where Atari800 is installed.

applies to SVGALIB target only which is deprecated and should no longer
be used. Normal binaries (curses, framebuffer, X11 and all others) are
not suid root.

> This bug exist in older Atari800 (i read source with version 1.3.0), in the 
> lasted version
> there isn't overflow in Aprint() function. It was rewrited!

yes, it was, because I were notified about this problem a year ago (see
below).

> Btw. Atari 1.3.3 and 1.3.2 are not vuln but i don't found any raport of this 
> bug what i writed here.

see the DOC/ChangeLog:

2003-11-13  Petr Stehlik  <pstehlik@xxxxxxxxxx>
* log.c: corrected buffer overflow found by Laios Mircea

I think it was found by Debian security team but I might be wrong (it's
more than year ago so I don't remember details).

> Best regards Adam Zabrocki (pi3).

thanks for the analysis. I'll fix the other problem (in the config file
parsing).

Petr