February 19, 2002

Security update to hanterm

Author: JT Smith

Posted on LWN.net: "A set of buffer overflow problems have been found in hanterm, a Hangul
terminal for X11 derived from xterm, that will read and display Korean
characters in its terminal window. The font handling code in hanterm
uses hard limited string variables but didn't check for boundaries.

This problem can be exploited by a malicious user to gain access to
the utmp group which is able to write the wtmp and utmp files. These
files record login and logout activities.


