GNU Sharutils Multiple Buffer Overflow Vulnerabilities
BID:11298
Info
GNU Sharutils Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11298 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1773 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2004 12:00AM |
| Updated: | Feb 22 2007 06:06PM |
| Credit: | These issues were discovered by Ulf Harnhammar and Florian Schilhabel. |
| Vulnerable: |
SGI ProPack 3.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 GNU sharutils 4.2.1 GNU sharutils 4.2 Avaya S8710 R2.0.1 Avaya S8710 R2.0.0 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya MN100 Avaya Intuity LX Avaya Converged Communications Server 2.0 |
| Not Vulnerable: | |
Discussion
GNU Sharutils Multiple Buffer Overflow Vulnerabilities
GNU Sharutils is affected by multiple buffer-overflow vulnerabilities because the software fails to verify the length of user-supplied strings prior to copying them into finite process buffers.
Successful exploitation would immediately produce a denial-of-service condition in the affected process. Attackers may also leverage this issue to execute code on the affected system with the privileges of the user that invoked the vulnerable application.
GNU Sharutils is affected by multiple buffer-overflow vulnerabilities because the software fails to verify the length of user-supplied strings prior to copying them into finite process buffers.
Successful exploitation would immediately produce a denial-of-service condition in the affected process. Attackers may also leverage this issue to execute code on the affected system with the privileges of the user that invoked the vulnerable application.
Exploit / POC
GNU Sharutils Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
GNU Sharutils Multiple Buffer Overflow Vulnerabilities
Solution:
Please see the referenced advisories for more information.
GNU sharutils 4.2.1
Solution:
Please see the referenced advisories for more information.
GNU sharutils 4.2.1
-
Fedora sharutils-4.2.1-18.1.FC2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora sharutils-4.2.1-18.1.FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora sharutils-4.2.1-22.1.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora sharutils-4.2.1-22.1.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora sharutils-debuginfo-4.2.1-18.1.FC2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora sharutils-debuginfo-4.2.1-18.1.FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora sharutils-debuginfo-4.2.1-22.1.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora sharutils-debuginfo-4.2.1-22.1.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Mandrake sharutils-4.2.1-14.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-14.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-14.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-14.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-14.1.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-14.1.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-17.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-17.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
RedHat sharutils-4.2.1-12.7.x.legacy.i386.rpm
RedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/sharutils-4.2 .1-12.7.x.legacy.i386.rpm -
RedHat sharutils-4.2.1-16.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/sharutils-4.2.1 -16.9.1.legacy.i386.rpm -
RedHat sharutils-4.2.1-17.2.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/sharutils-4.2.1 -17.2.legacy.i386.rpm
References
GNU Sharutils Multiple Buffer Overflow Vulnerabilities
References:
References:
- ASA-2005-135 - sharutils (Avaya)
- GNU Sharutils Home Page (GNU)
- RHSA-2005:377-07 - sharutils security update (Red Hat)