EFFingerD Remote Buffer Overflow Vulnerability
BID:10304
Info
EFFingerD Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 10304 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2004 12:00AM |
| Updated: | May 08 2004 12:00AM |
| Credit: | Discovery of this vulnerability ha been credited to [email protected]. |
| Vulnerable: |
efFingerD efFingerD 0.2.12 |
| Not Vulnerable: | |
Discussion
EFFingerD Remote Buffer Overflow Vulnerability
efFingerD has been reported prone to a remote buffer overflow vulnerability. The problem occurs due to insufficient bounds checking performed when handling requests.
As a result, an attacker may be capable of corrupting sensitive data such as a return address, and thereby effectively control the execution flow of the program. This would ultimately allow for the execution of arbitrary code. Immediate consequences of exploitation of this issue may result in denial of service.
efFingerD has been reported prone to a remote buffer overflow vulnerability. The problem occurs due to insufficient bounds checking performed when handling requests.
As a result, an attacker may be capable of corrupting sensitive data such as a return address, and thereby effectively control the execution flow of the program. This would ultimately allow for the execution of arbitrary code. Immediate consequences of exploitation of this issue may result in denial of service.
Exploit / POC
EFFingerD Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EFFingerD Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.