Sysklogd Crunch_List Buffer Overrun Vulnerability
BID:10238
Info
Sysklogd Crunch_List Buffer Overrun Vulnerability
| Bugtraq ID: | 10238 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 29 2004 12:00AM |
| Updated: | Apr 29 2004 12:00AM |
| Credit: | Discovery is credited to Steve Grubb. |
| Vulnerable: |
Sysklogd Sysklogd 1.4.1 Sysklogd Sysklogd 1.4 Sysklogd Sysklogd 1.3 Sysklogd Sysklogd 1.2 Sysklogd Sysklogd 1.1 |
| Not Vulnerable: | |
Discussion
Sysklogd Crunch_List Buffer Overrun Vulnerability
Sysklogd has been reported to prone to a buffer overrun vulnerability.
This condition may theoretically permit a local attacker to crash the server. It is not believed that this condition may be exploited to execute arbitrary with elevated privileges, since the syslogd component may not be installed with setuid/setgid permissions, though this has not been confirmed.
Sysklogd has been reported to prone to a buffer overrun vulnerability.
This condition may theoretically permit a local attacker to crash the server. It is not believed that this condition may be exploited to execute arbitrary with elevated privileges, since the syslogd component may not be installed with setuid/setgid permissions, though this has not been confirmed.
Exploit / POC
Sysklogd Crunch_List Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sysklogd Crunch_List Buffer Overrun Vulnerability
Solution:
Mandrake has released advisory MDKSA-2004:038 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Openwall have released patches for Owl-current which are available through CVS.
Slackware has released advisory SSA:2004-124-02 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Sysklogd Sysklogd 1.4.1
Solution:
Mandrake has released advisory MDKSA-2004:038 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Openwall have released patches for Owl-current which are available through CVS.
Slackware has released advisory SSA:2004-124-02 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Sysklogd Sysklogd 1.4.1
-
Mandrake sysklogd-1.4.1-3.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sysklogd-1.4.1-3.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sysklogd-1.4.1-3.1.M82mdk.i586.rpm
Mandrake Multi Network Firewall 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sysklogd-1.4.1-5.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sysklogd-1.4.1-5.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sysklogd-1.4.1-5.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sysklogd-1.4.1-5.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sysklogd-1.4.1-5.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Slackware sysklogd-1.4.1-i386-7.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/s ysklogd-1.4.1-i386-7.tgz -
Slackware sysklogd-1.4.1-i386-9.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/s ysklogd-1.4.1-i386-9.tgz -
Slackware sysklogd-1.4.1-i486-9.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/s ysklogd-1.4.1-i486-9.tgz