Pavuk Remote Stack-Based Buffer Overrun Vulnerability
BID:10633
Info
Pavuk Remote Stack-Based Buffer Overrun Vulnerability
| Bugtraq ID: | 10633 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0456 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | This vulnerability was announced in a vendor advisory. |
| Vulnerable: |
Pavuk Pavuk 0.9pl28i Pavuk Pavuk 0.928r1 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Gentoo Linux 1.2 Gentoo Linux 1.1 a Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
Pavuk Pavuk 0.928r2 |
Discussion
Pavuk Remote Stack-Based Buffer Overrun Vulnerability
Pavuk is reported prone to a remote buffer overrun vulnerability. It is reported that the issue exists due to a lack of boundary checks performed on third party data, that is received from remote HTTP servers, before the data is copied into a finite stack-based buffer.
Ultimately a remote malicious site may exploit this condition to execute arbitrary code in the context of the user who is running the vulnerable Pavuk software.
Pavuk is reported prone to a remote buffer overrun vulnerability. It is reported that the issue exists due to a lack of boundary checks performed on third party data, that is received from remote HTTP servers, before the data is copied into a finite stack-based buffer.
Ultimately a remote malicious site may exploit this condition to execute arbitrary code in the context of the user who is running the vulnerable Pavuk software.
Exploit / POC
Pavuk Remote Stack-Based Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Pavuk Remote Stack-Based Buffer Overrun Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200406-22) and updated eBuilds to address this issue; Gentoo users who are running Pavuk are advised to execute the following series of commands as a superuser to apply the fixes:
emerge sync
emerge -pv ">=net-misc/pavuk-0.9.28-r2"
emerge ">="net-misc/pavuk-0.9.28-r2
Debian GNU/Linux has released advisory DSA 527-1 addressing this issue. Please see the referenced advisory for further information.
Pavuk Pavuk 0.9pl28i
Solution:
Gentoo has released an advisory (GLSA 200406-22) and updated eBuilds to address this issue; Gentoo users who are running Pavuk are advised to execute the following series of commands as a superuser to apply the fixes:
emerge sync
emerge -pv ">=net-misc/pavuk-0.9.28-r2"
emerge ">="net-misc/pavuk-0.9.28-r2
Debian GNU/Linux has released advisory DSA 527-1 addressing this issue. Please see the referenced advisory for further information.
Pavuk Pavuk 0.9pl28i
-
Debian pavuk_0.9pl28-1woody1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_alpha.deb -
Debian pavuk_0.9pl28-1woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_arm.deb -
Debian pavuk_0.9pl28-1woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_hppa.deb -
Debian pavuk_0.9pl28-1woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_i386.deb -
Debian pavuk_0.9pl28-1woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_ia64.deb -
Debian pavuk_0.9pl28-1woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_m68k.deb -
Debian pavuk_0.9pl28-1woody1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_mips.deb -
Debian pavuk_0.9pl28-1woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_mipsel.deb -
Debian pavuk_0.9pl28-1woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_powerpc.deb -
Debian pavuk_0.9pl28-1woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_s390.deb -
Debian pavuk_0.9pl28-1woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/p/pavuk/pavuk_0.9pl28-1wo ody1_sparc.deb