JWhois Double Free Memory Corruption Vulnerability
BID:11656
Info
JWhois Double Free Memory Corruption Vulnerability
| Bugtraq ID: | 11656 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2004 12:00AM |
| Updated: | Nov 10 2004 12:00AM |
| Credit: | This vulnerability was reported by Dams. |
| Vulnerable: |
GNU jwhois 3.2.2 |
| Not Vulnerable: | |
Discussion
JWhois Double Free Memory Corruption Vulnerability
It is reported that jwhois is susceptible to a double free vulnerability.
If jwhois attempts to process whois requests that result in more than one redirection, it is reported that a double free condition will occur.
It is conjectured that it may be possible for remote attackers to exploit this vulnerability to write to arbitrary locations in memory, facilitating the execution of attacker-supplied code. This has not been confirmed.
This vulnerability may not actually be exploitable. This BID will be updated or retired as further information is disclosed.
It is reported that jwhois is susceptible to a double free vulnerability.
If jwhois attempts to process whois requests that result in more than one redirection, it is reported that a double free condition will occur.
It is conjectured that it may be possible for remote attackers to exploit this vulnerability to write to arbitrary locations in memory, facilitating the execution of attacker-supplied code. This has not been confirmed.
This vulnerability may not actually be exploitable. This BID will be updated or retired as further information is disclosed.
Exploit / POC
JWhois Double Free Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
JWhois Double Free Memory Corruption Vulnerability
Solution:
RedHat has released advisory FEDORA-2004-406 to address this issue in Fedora Core 3. Please see the referenced advisory for further information.
GNU jwhois 3.2.2
Solution:
RedHat has released advisory FEDORA-2004-406 to address this issue in Fedora Core 3. Please see the referenced advisory for further information.
GNU jwhois 3.2.2
-
Fedora jwhois-3.2.2-6.FC3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora jwhois-3.2.2-6.FC3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora jwhois-debuginfo-3.2.2-6.FC3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora jwhois-debuginfo-3.2.2-6.FC3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
References
JWhois Double Free Memory Corruption Vulnerability
References:
References: