VICE Monitor Memory Dump Format String Vulnerability
BID:10543
Info
VICE Monitor Memory Dump Format String Vulnerability
| Bugtraq ID: | 10543 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0453 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 14 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this vulnerability is credited to Spiro Trikaliotis <[email protected]>. |
| Vulnerable: |
VICE VICE 1.14 VICE VICE 1.13 VICE VICE 1.12 VICE VICE 1.11 VICE VICE 1.10 VICE VICE 1.9 VICE VICE 1.8 VICE VICE 1.7 VICE VICE 1.6 |
| Not Vulnerable: |
VICE VICE 1.15 |
Discussion
VICE Monitor Memory Dump Format String Vulnerability
VICE monitor is reported prone to a format string vulnerability. The issue is reported to exist when output from the monitor "memory dump" command is displayed. Memory contents are used without sanitization as the format string for a print formatted function. As a result, malicious memory contents containing format specifiers will be interpreted literally when a memory dump is performed; this may result in attacker-specified memory being corrupted in the context of the user who is running the VICE monitor memory dump command.
VICE monitor is reported prone to a format string vulnerability. The issue is reported to exist when output from the monitor "memory dump" command is displayed. Memory contents are used without sanitization as the format string for a print formatted function. As a result, malicious memory contents containing format specifiers will be interpreted literally when a memory dump is performed; this may result in attacker-specified memory being corrupted in the context of the user who is running the VICE monitor memory dump command.
Exploit / POC
VICE Monitor Memory Dump Format String Vulnerability
It has been reported that this issue is being exploited in the wild, although at this time these exploits are not publically available.
It has been reported that this issue is being exploited in the wild, although at this time these exploits are not publically available.
Solution / Fix
VICE Monitor Memory Dump Format String Vulnerability
Solution:
Spiro Trikaliotis <[email protected]>, a developer for the VICE project, supplied the following supported patch:
http://downloads.securityfocus.com/vulnerabilities/patches/vice-1.14-mon-vuln.patch
VICE version 1.15 has been released and resolves this issue.
VICE VICE 1.10
VICE VICE 1.11
VICE VICE 1.12
VICE VICE 1.13
VICE VICE 1.14
VICE VICE 1.6
VICE VICE 1.7
VICE VICE 1.8
VICE VICE 1.9
Solution:
Spiro Trikaliotis <[email protected]>, a developer for the VICE project, supplied the following supported patch:
http://downloads.securityfocus.com/vulnerabilities/patches/vice-1.14-mon-vuln.patch
VICE version 1.15 has been released and resolves this issue.
VICE VICE 1.10
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.11
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.12
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.13
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.14
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.6
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.7
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.8
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
VICE VICE 1.9
-
VICE vice-1.15.tar.gz
ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
References
VICE Monitor Memory Dump Format String Vulnerability
References:
References:
- VICE Emulator Homepage (VICE)
- VSA-2004-1-VICE monitor memory dump format string vulnerability (VICE Security Advisory )
- VICE emulator format string vulnerability (Spiro Trikaliotis
)