[原文]Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.

[CNNVD]多个Linux供应商KON (Kanji On Console)缓冲区溢出漏洞(CNNVD-200006-084)

        Linux Kanji on Console (KON)包中kon程序存在缓冲区溢出漏洞。本地用户借助long -StartupMessage参数可以提升根特权。

This vulnerability was posted to the Bugtraq mailing list by Chris Evans <> on Mon, Jun 19 2000. A detailed followup with an exploit was developed and posted by "Black Sphere" <> on Fri, Aug 4 2000.

- 漏洞讨论

KON (Kanji On Console) is a package for displaying Kanji text under Linux and comes with two suid binaries which are vulnerable to buffer overflows. "fld", one of the vulnerable programs, accepts options input from a text file. Through this mechanism it is possible to input arbitrary code into the stack and spawn a root shell. The other binary, kon, suffers from a buffer overflow as well. The buffer overflow in kon can be exploited via the -StartupMessage command line option, and fld via the command line options: -t bdf &lt;file to be read&gt;

