Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdcmd, (3) afd_ctrl, (4) init_afd, (5) mafd, (6) mon_ctrl, (7) show_olog, or (8) udc.
| Software | From | Fixed in |
|---|---|---|
| afd / afd | 1.2.1 | 1.2.1.x |
| afd / afd | 1.2.2 | 1.2.2.x |
| afd / afd | 1.2.13 | 1.2.13.x |
| afd / afd | 1.2.7 | 1.2.7.x |
| afd / afd | 1.2.10 | 1.2.10.x |
| afd / afd | 1.2.12 | 1.2.12.x |
| afd / afd | 1.2.14 | 1.2.14.x |
| afd / afd | 1.2.4 | 1.2.4.x |
| afd / afd | 1.2.8 | 1.2.8.x |
| afd / afd | 1.2.11 | 1.2.11.x |
| afd / afd | 1.2.5 | 1.2.5.x |
| afd / afd | 1.2.6 | 1.2.6.x |
| afd / afd | 1.2.9 | 1.2.9.x |
| afd / afd | 1.2 | 1.2.x |
| afd / afd | 1.2.3 | 1.2.3.x |