Super Local Format String Vulnerability
BID:10575
Info
Super Local Format String Vulnerability
| Bugtraq ID: | 10575 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0579 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 19 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery is credited to Max Vozeler. |
| Vulnerable: |
William Deich super 3.19 William Deich super 3.18 William Deich super 3.17 William Deich super 3.16 William Deich super 3.12 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Super Local Format String Vulnerability
super is prone to a locally exploitable format string vulnerability. The problem occurs due to the incorrect usage of programming functions designed to take formatted arguments.
Because of this, attacker supplied format specifiers will be interpreted literally by the vulnerable program. This vulnerability may provide a conduit for an attacker to influence arbitrary writes into process memory space. Ultimately this vulnerability may be exploited in order to have arbitrary code executed with superuser privileges.
**Update: This issue was originally believed to be a duplicate of BID 5367, however further reports indicate that this is not the case. Therefore this BID is reinstated.
super is prone to a locally exploitable format string vulnerability. The problem occurs due to the incorrect usage of programming functions designed to take formatted arguments.
Because of this, attacker supplied format specifiers will be interpreted literally by the vulnerable program. This vulnerability may provide a conduit for an attacker to influence arbitrary writes into process memory space. Ultimately this vulnerability may be exploited in order to have arbitrary code executed with superuser privileges.
**Update: This issue was originally believed to be a duplicate of BID 5367, however further reports indicate that this is not the case. Therefore this BID is reinstated.
Exploit / POC
Super Local Format String Vulnerability
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
Solution / Fix
Super Local Format String Vulnerability
Solution:
Debian has released an advisory (DSA 522-1) and fixes for this issue. See the referenced advisory for links to fixed packages.
Solution:
Debian has released an advisory (DSA 522-1) and fixes for this issue. See the referenced advisory for links to fixed packages.