SERCD, SREDIRD Buffer Overflow Vulnerability
BID:11033
Info
SERCD, SREDIRD Buffer Overflow Vulnerability
| Bugtraq ID: | 11033 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2004 12:00AM |
| Updated: | Aug 01 2004 12:00AM |
| Credit: | Max Vozeler <[email protected]> disclosed this vulnerability to the vendors. |
| Vulnerable: |
Peter �?strand SERCD 2.3 .0 Denis Sbragion sredird 2.2.1 Denis Sbragion sredird 2.2 Denis Sbragion sredird 2.1 Denis Sbragion sredird 2.0 Denis Sbragion sredird 1.1.8 Denis Sbragion sredird 1.1.7 Denis Sbragion sredird 1.1.6 Denis Sbragion sredird 1.0 |
| Not Vulnerable: |
Peter �?strand SERCD 2.3.1 |
Discussion
SERCD, SREDIRD Buffer Overflow Vulnerability
It is reported that SERCD and SREDIRD both contain a buffer overflow vulnerability. This issue is due to a failure of the applications to properly perform bounds checks on user-supplied input before copying it to a buffer of finite size.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the affected package. These processes are commonly run as the superuser in order to access the serial port.
Versions of SERCD prior to 2.3.1, and all known versions of SREDIRD are reported susceptible to this vulnerability.
BID 11002 was split into this BID and BID 11031.
It is reported that SERCD and SREDIRD both contain a buffer overflow vulnerability. This issue is due to a failure of the applications to properly perform bounds checks on user-supplied input before copying it to a buffer of finite size.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the affected package. These processes are commonly run as the superuser in order to access the serial port.
Versions of SERCD prior to 2.3.1, and all known versions of SREDIRD are reported susceptible to this vulnerability.
BID 11002 was split into this BID and BID 11031.
Exploit / POC
SERCD, SREDIRD Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SERCD, SREDIRD Buffer Overflow Vulnerability
Solution:
The vendor has released version 2.3.1 of the package to address this issue:
Peter �?strand SERCD 2.3 .0
Solution:
The vendor has released version 2.3.1 of the package to address this issue:
Peter �?strand SERCD 2.3 .0
-
Peter �?strand sercd-2.3.1.tar.gz
http://www.lysator.liu.se/~astrand/projects/sercd/sercd-2.3.1.tar.gz
References
SERCD, SREDIRD Buffer Overflow Vulnerability
References:
References:
- CVS Log for sercd.c revision 1.9 (Peter �?strand)
- SERCD Home Page (Peter �?strand)
- sredird Homepage (Denis Sbragion)
- sredird LogMsg() Format String Bug and HandleCPCCommand() Buffer Overflow May Le (SecurityTracker)