PvPGN Remote Buffer Overflow Vulnerability
BID:11074
Info
PvPGN Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11074 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2004 12:00AM |
| Updated: | Aug 29 2004 12:00AM |
| Credit: | This issue was discovered by dizzy. |
| Vulnerable: |
PvPGN PvPGN 1.6.5 PvPGN PvPGN 1.6.4 PvPGN PvPGN 1.6.3 PvPGN PvPGN 1.6.2 PvPGN PvPGN 1.6.1 PvPGN PvPGN 1.6 .0 |
| Not Vulnerable: | |
Discussion
PvPGN Remote Buffer Overflow Vulnerability
PvPGN is reported prone to a remote buffer overflow vulnerability. This issue can allow an attacker to execute arbitrary code to gain unauthorized access to a vulnerable computer.
An attacker can trigger this vulnerability by supplying an excessively long string value through the 'watchall' and 'unwatchall' commands.
All versions of PvPGN including 1.6.5 and prior are affected by this vulnerability.
PvPGN is reported prone to a remote buffer overflow vulnerability. This issue can allow an attacker to execute arbitrary code to gain unauthorized access to a vulnerable computer.
An attacker can trigger this vulnerability by supplying an excessively long string value through the 'watchall' and 'unwatchall' commands.
All versions of PvPGN including 1.6.5 and prior are affected by this vulnerability.
Exploit / POC
PvPGN Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PvPGN Remote Buffer Overflow Vulnerability
Solution:
This issue has been addressed in the CVS. A patch is available as well.
PvPGN PvPGN 1.6 .0
PvPGN PvPGN 1.6.1
PvPGN PvPGN 1.6.2
PvPGN PvPGN 1.6.3
PvPGN PvPGN 1.6.4
PvPGN PvPGN 1.6.5
Solution:
This issue has been addressed in the CVS. A patch is available as well.
PvPGN PvPGN 1.6 .0
-
PvPGN pvpgn-1.6-watchall.patch
http://sourceforge.net/tracker/download.php?group_id=53514&atid=470607 &file_id=99656&aid=1018716
PvPGN PvPGN 1.6.1
-
PvPGN pvpgn-1.6-watchall.patch
http://sourceforge.net/tracker/download.php?group_id=53514&atid=470607 &file_id=99656&aid=1018716
PvPGN PvPGN 1.6.2
-
PvPGN pvpgn-1.6-watchall.patch
http://sourceforge.net/tracker/download.php?group_id=53514&atid=470607 &file_id=99656&aid=1018716
PvPGN PvPGN 1.6.3
-
PvPGN pvpgn-1.6-watchall.patch
http://sourceforge.net/tracker/download.php?group_id=53514&atid=470607 &file_id=99656&aid=1018716
PvPGN PvPGN 1.6.4
-
PvPGN pvpgn-1.6-watchall.patch
http://sourceforge.net/tracker/download.php?group_id=53514&atid=470607 &file_id=99656&aid=1018716
PvPGN PvPGN 1.6.5
-
PvPGN pvpgn-1.6-watchall.patch
http://sourceforge.net/tracker/download.php?group_id=53514&atid=470607 &file_id=99656&aid=1018716
References
PvPGN Remote Buffer Overflow Vulnerability
References:
References: