EZ-IPupdate Remote Format String Vulnerability
BID:11657
Info
EZ-IPupdate Remote Format String Vulnerability
| Bugtraq ID: | 11657 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0980 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery credited to Ulf Harnhammar. |
| Vulnerable: |
Gentoo Linux Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Angus Mackay ez-ipupdate 3.0.11 b8 Angus Mackay ez-ipupdate 3.0.11 b5 |
| Not Vulnerable: | |
Discussion
EZ-IPupdate Remote Format String Vulnerability
EZ-IPupdate is vulnerable to a remotely exploitable format string vulnerability when running in daemon-mode. The vulnerability is present even if "quiet" mode is enabled.
EZ-IPupdate is vulnerable to a remotely exploitable format string vulnerability when running in daemon-mode. The vulnerability is present even if "quiet" mode is enabled.
Exploit / POC
EZ-IPupdate Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EZ-IPupdate Remote Format String Vulnerability
Solution:
Mandrake has issued fixes in advisory MDKSA-2004:129. See the reference section for the advisory. SuSE fixes for SuSE Linux 9.2 i386 are available at:
http://www.suse.de/en/private/download/updates/92_i386.html
Gentoo Linux has released advisory GLSA 200411-20 to address this issue. Users of affected packages are urged to execute the following with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-dns/ez-ipupdate-3.0.11_beta8-r1"
Please see the referenced advisory for further information.
Debian has released an advisory (DSA 592-1) and fixes for this issue. Please see the referenced advisory for information on obtaining fixes.
Angus Mackay ez-ipupdate 3.0.11 b5
Angus Mackay ez-ipupdate 3.0.11 b8
Solution:
Mandrake has issued fixes in advisory MDKSA-2004:129. See the reference section for the advisory. SuSE fixes for SuSE Linux 9.2 i386 are available at:
http://www.suse.de/en/private/download/updates/92_i386.html
Gentoo Linux has released advisory GLSA 200411-20 to address this issue. Users of affected packages are urged to execute the following with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-dns/ez-ipupdate-3.0.11_beta8-r1"
Please see the referenced advisory for further information.
Debian has released an advisory (DSA 592-1) and fixes for this issue. Please see the referenced advisory for information on obtaining fixes.
Angus Mackay ez-ipupdate 3.0.11 b5
-
Debian ez-ipupdate_3.0.11b5-1woody2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_alpha.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_arm.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_hppa.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_i386.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_ia64.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_m68k.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_mips.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_mipsel.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_powerpc.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_s390.deb -
Debian ez-ipupdate_3.0.11b5-1woody2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate _3.0.11b5-1woody2_sparc.deb
Angus Mackay ez-ipupdate 3.0.11 b8
-
Mandrake ez-ipupdate-3.0.11b8-2.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ez-ipupdate-3.0.11b8-2.1.M82mdk.i586.rpm
Mandrake Multi Network Firewall 8.2
http://www.mandrakesecure.net/en/ftp.php
References
EZ-IPupdate Remote Format String Vulnerability
References:
References:
- ez-ipupdate Homepage (Angus Mackay)
- SUSE LINUX 9.2 (i386): Patches, Updates, Bugfixes (S.u.S.E.)