APSIS Pound Remote Format String Vulnerability
BID:10267
Info
APSIS Pound Remote Format String Vulnerability
| Bugtraq ID: | 10267 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2004 12:00AM |
| Updated: | May 03 2004 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Akira Higuchi. |
| Vulnerable: |
Gentoo Linux 1.4 APSIS Pound 1.5 |
| Not Vulnerable: |
APSIS Pound 1.7 APSIS Pound 1.6 |
Discussion
APSIS Pound Remote Format String Vulnerability
APSIS Pound has been found to be prone to a remote format string vulnerability. The problem presents itself when Pound handles certain requests containing embedded format string specifiers.
Ultimately this vulnerability could allow for execution of arbitrary code on the system implementing the affected software, which would occur in the security context of the server process.
APSIS Pound has been found to be prone to a remote format string vulnerability. The problem presents itself when Pound handles certain requests containing embedded format string specifiers.
Ultimately this vulnerability could allow for execution of arbitrary code on the system implementing the affected software, which would occur in the security context of the server process.
Exploit / POC
APSIS Pound Remote Format String Vulnerability
An exploit has been released:
An exploit has been released:
Solution / Fix
APSIS Pound Remote Format String Vulnerability
Solution:
The vendor has released an upgrade to address this issue:
Gentoo Linux has released an advisory (GLSA 200405-08) that addresses this issue. Please see the referenced advisory for further information. It is advised that administrators execute as superuser to update Pound:
emerge sync
emerge -pv ">=net-www/pound-1.6"
emerge ">=net-www/pound-1.6"
APSIS Pound 1.5
Solution:
The vendor has released an upgrade to address this issue:
Gentoo Linux has released an advisory (GLSA 200405-08) that addresses this issue. Please see the referenced advisory for further information. It is advised that administrators execute as superuser to update Pound:
emerge sync
emerge -pv ">=net-www/pound-1.6"
emerge ">=net-www/pound-1.6"
APSIS Pound 1.5
-
APSIS Pound-current.tgz
http://www.apsis.ch/pound/Pound-current.tgz
References
APSIS Pound Remote Format String Vulnerability
References:
References:
- Pound Errata (APSIS)
- Pound Homepage (APSIS)