ProZilla Multiple Remote Buffer Overflow Vulnerabilities
BID:11734
Info
ProZilla Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11734 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1120 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Robert Muchacki <[email protected]> reported these issues to Gentoo. Further information was disclosed by Florian Schilhabel, and Dan Margolis. |
| Vulnerable: |
Prozilla ProZilla Download Accelerator 1.3.6 Prozilla ProZilla Download Accelerator 1.3.5 .2 Prozilla ProZilla Download Accelerator 1.3.5 .1 Prozilla ProZilla Download Accelerator 1.3.5 Prozilla ProZilla Download Accelerator 1.3.4 Prozilla ProZilla Download Accelerator 1.3.3 .x Prozilla ProZilla Download Accelerator 1.3.3 Prozilla ProZilla Download Accelerator 1.3.2 Prozilla ProZilla Download Accelerator 1.3.1 Prozilla ProZilla Download Accelerator 1.3 .0 Prozilla ProZilla Download Accelerator 1.0 x |
| Not Vulnerable: | |
Discussion
ProZilla Multiple Remote Buffer Overflow Vulnerabilities
It is reported that multiple buffer overflow vulnerabilities exist in ProZilla. These issues are due to a failure of the application to properly bounds check user-supplied input prior to copying it into fixed sized memory buffers.
These vulnerabilities allow remote attackers to execute arbitrary code in the context of a user running the affected application. A victim user is required to attempt to download files from an attacker-controlled server for an exploit to succeed.
It is reported that multiple buffer overflow vulnerabilities exist in ProZilla. These issues are due to a failure of the application to properly bounds check user-supplied input prior to copying it into fixed sized memory buffers.
These vulnerabilities allow remote attackers to execute arbitrary code in the context of a user running the affected application. A victim user is required to attempt to download files from an attacker-controlled server for an exploit to succeed.
Exploit / POC
ProZilla Multiple Remote Buffer Overflow Vulnerabilities
An example exploits have been provided by Florian Schilhabel and Serkan Akpolat:
An example exploits have been provided by Florian Schilhabel and Serkan Akpolat:
Solution / Fix
ProZilla Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Gentoo Linux has released advisory GLSA 200411-31 describing this issue. Please see the referenced advisory for further information. Gentoo Linux does not have a fix available at this time, and they recommend against using ProZilla until such a fix is provided by the vendor.
Debian has released advisory DSA 663-1 to address these issues. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Prozilla ProZilla Download Accelerator 1.3.6
Solution:
Gentoo Linux has released advisory GLSA 200411-31 describing this issue. Please see the referenced advisory for further information. Gentoo Linux does not have a fix available at this time, and they recommend against using ProZilla until such a fix is provided by the vendor.
Debian has released advisory DSA 663-1 to address these issues. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Prozilla ProZilla Download Accelerator 1.3.6
-
Debian prozilla_1.3.6-3woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_alpha.deb -
Debian prozilla_1.3.6-3woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_arm.deb -
Debian prozilla_1.3.6-3woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_hppa.deb -
Debian prozilla_1.3.6-3woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_i386.deb -
Debian prozilla_1.3.6-3woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_ia64.deb -
Debian prozilla_1.3.6-3woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_m68k.deb -
Debian prozilla_1.3.6-3woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_mips.deb -
Debian prozilla_1.3.6-3woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_mipsel.deb -
Debian prozilla_1.3.6-3woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_powerpc.deb -
Debian prozilla_1.3.6-3woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_s390.deb -
Debian prozilla_1.3.6-3woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody1_sparc.deb
References
ProZilla Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- Bugzilla Bug 70090 - www-client/prozilla: multiple vulnerabilities (Gentoo)
- ProZIlla Home Page (ProZIlla)
- Prozilla Remote Exploit (Serkan Akpolat
)