L2TPD Write_Packet Block BSS based Buffer Overflow Vulnerability
BID:10466
Info
L2TPD Write_Packet Block BSS based Buffer Overflow Vulnerability
| Bugtraq ID: | 10466 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0649 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Disclosure of this issue is credited to Thomas Walpuski <[email protected]>. |
| Vulnerable: |
l2tpd l2tpd 0.69 l2tpd l2tpd 0.68 l2tpd l2tpd 0.67 l2tpd l2tpd 0.66 l2tpd l2tpd 0.65 l2tpd l2tpd 0.64 l2tpd l2tpd 0.63 l2tpd l2tpd 0.62 Gentoo Linux 1.4 |
| Not Vulnerable: | |
Discussion
L2TPD Write_Packet Block BSS based Buffer Overflow Vulnerability
l2tpd is reportedly affected by a BSS (block started by symbol) based buffer overflow vulnerability. This issue is due to a failure of the application to properly validate user supplied string lengths.
This issue has been reported to be extremely difficult to exploit; code execution is extremely unlikely. This issue might be leveraged to cause the affected application to behave unpredictably and perhaps crash.
l2tpd is reportedly affected by a BSS (block started by symbol) based buffer overflow vulnerability. This issue is due to a failure of the application to properly validate user supplied string lengths.
This issue has been reported to be extremely difficult to exploit; code execution is extremely unlikely. This issue might be leveraged to cause the affected application to behave unpredictably and perhaps crash.
Exploit / POC
L2TPD Write_Packet Block BSS based Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
L2TPD Write_Packet Block BSS based Buffer Overflow Vulnerability
Solution:
Debian has released security advisory DSA 530-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo has released advisory GLSA 200407-17 dealing with this issue. They have advised that users take the following actions and upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-l2tpd-0.69-r2"
# emerge ">=net-l2tpd-0.69-r2"
For more information, please see the referenced Gentoo advisory.
l2tpd l2tpd 0.67
Solution:
Debian has released security advisory DSA 530-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo has released advisory GLSA 200407-17 dealing with this issue. They have advised that users take the following actions and upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-l2tpd-0.69-r2"
# emerge ">=net-l2tpd-0.69-r2"
For more information, please see the referenced Gentoo advisory.
l2tpd l2tpd 0.67
-
Debian l2tpd_0.67-1.2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_ar m.deb -
Debian l2tpd_0.67-1.2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_hp pa.deb -
Debian l2tpd_0.67-1.2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_i3 86.deb -
Debian l2tpd_0.67-1.2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_ia 64.deb -
Debian l2tpd_0.67-1.2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_m6 8k.deb -
Debian l2tpd_0.67-1.2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_mi ps.deb -
Debian l2tpd_0.67-1.2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_mi psel.deb -
Debian l2tpd_0.67-1.2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_po werpc.deb -
Debian l2tpd_0.67-1.2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_s3 90.deb -
Debian l2tpd_0.67-1.2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.2_sp arc.deb
References
L2TPD Write_Packet Block BSS based Buffer Overflow Vulnerability
References:
References:
- l2tpd Homepage (l2tpd)
- bss-based buffer overflow in l2tpd (Thomas Walpuski
)