Rlpr msg() Function Multiple Vulnerabilities
BID:10578
Info
Rlpr msg() Function Multiple Vulnerabilities
| Bugtraq ID: | 10578 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0393 CVE-2004-0454 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | The format string issue was discovered by [email protected]. The buffer overflow issue was disclosed by Debian. |
| Vulnerable: |
rlpr rlpr 2.0 4 rlpr rlpr 2.0 3 rlpr rlpr 2.0 2 rlpr rlpr 2.0 1 rlpr rlpr 2.0 |
| Not Vulnerable: | |
Discussion
Rlpr msg() Function Multiple Vulnerabilities
It is reported that rlpr is prone to multiple vulnerabilities. These vulnerabilities can allow a remote attacker to execute arbitrary code in order to gain unauthorized access.
The application is affected by a format string vulnerability. This vulnerability presents itself due to insufficient sanitization of user-supplied data through the 'msg()' function.
The 'msg()' function is also affected by a buffer overflow vulnerability. This issue occurs due to insufficient boundary checking and may also be exploited to gain unauthorized access to a vulnerable computer.
rlpr versions 2.04 and prior are affected by these issues.
It is reported that rlpr is prone to multiple vulnerabilities. These vulnerabilities can allow a remote attacker to execute arbitrary code in order to gain unauthorized access.
The application is affected by a format string vulnerability. This vulnerability presents itself due to insufficient sanitization of user-supplied data through the 'msg()' function.
The 'msg()' function is also affected by a buffer overflow vulnerability. This issue occurs due to insufficient boundary checking and may also be exploited to gain unauthorized access to a vulnerable computer.
rlpr versions 2.04 and prior are affected by these issues.
Exploit / POC
Rlpr msg() Function Multiple Vulnerabilities
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
An exploit has been provided by [email protected].
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
An exploit has been provided by [email protected].
Solution / Fix
Rlpr msg() Function Multiple Vulnerabilities
Solution:
Debian has released an advisory (DSA 524-1) to address these issues. Please see the referenced advisory for more information about obtaining fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
rlpr rlpr 2.0 2
Solution:
Debian has released an advisory (DSA 524-1) to address these issues. Please see the referenced advisory for more information about obtaining fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
rlpr rlpr 2.0 2
-
Debian rlpr_2.02-7woody1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ alpha.deb -
Debian rlpr_2.02-7woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ arm.deb -
Debian rlpr_2.02-7woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ hppa.deb -
Debian rlpr_2.02-7woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ i386.deb -
Debian rlpr_2.02-7woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ ia64.deb -
Debian rlpr_2.02-7woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ m68k.deb -
Debian rlpr_2.02-7woody1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ mips.deb -
Debian rlpr_2.02-7woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ mipsel.deb -
Debian rlpr_2.02-7woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ powerpc.deb -
Debian rlpr_2.02-7woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ s390.deb -
Debian rlpr_2.02-7woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/r/rlpr/rlpr_2.02-7woody1_ sparc.deb
References
Rlpr msg() Function Multiple Vulnerabilities
References:
References:
- rlpr Homepage (rlpr)
- rlprd format string exploit (CORE Security)
- Rlpr Advisory ([email protected])