WWW-SQL Include Command Buffer Overflow Vulnerability
BID:10577
Info
WWW-SQL Include Command Buffer Overflow Vulnerability
| Bugtraq ID: | 10577 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0455 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 21 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this issue is credited to Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
James Henstridge www-sql 0.5.7 |
| Not Vulnerable: | |
Discussion
WWW-SQL Include Command Buffer Overflow Vulnerability
www-sql is reportedly vulnerable to a buffer overflow vulnerability in its include command implementation. This issue arises due to a failure of the affected application to properly handle user-supplied strings when copying them into finite stack-based buffers.
An attacker can leverage this issue to manipulate process memory; by supplying program code as well as a specially selected memory address an attacker gain control of the processes execution flow allowing for arbitrary code execution.
www-sql is reportedly vulnerable to a buffer overflow vulnerability in its include command implementation. This issue arises due to a failure of the affected application to properly handle user-supplied strings when copying them into finite stack-based buffers.
An attacker can leverage this issue to manipulate process memory; by supplying program code as well as a specially selected memory address an attacker gain control of the processes execution flow allowing for arbitrary code execution.
Exploit / POC
WWW-SQL Include Command Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WWW-SQL Include Command Buffer Overflow Vulnerability
Solution:
Debian Linux has released security advisory DSA 523-1 dealing with this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian Linux has released security advisory DSA 523-1 dealing with this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WWW-SQL Include Command Buffer Overflow Vulnerability
References:
References:
- The WWW-SQL Home Page (James Henstridge)