Open DC Hub Remote Buffer Overflow Vulnerability
BID:11747
Info
Open DC Hub Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11747 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2004 12:00AM |
| Updated: | Nov 24 2004 12:00AM |
| Credit: | "Donato Ferrante" <[email protected]> is credited with discovery of this issue. |
| Vulnerable: |
Open DC Hub Direct Connect Peer-to-peer Client 0.7.14 |
| Not Vulnerable: | |
Discussion
Open DC Hub Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability reportedly affects the Open DC Hub. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
A remote buffer overflow vulnerability reportedly affects the Open DC Hub. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
Open DC Hub Remote Buffer Overflow Vulnerability
The following proof of concept has been made available:
The following proof of concept has been made available:
Solution / Fix
Open DC Hub Remote Buffer Overflow Vulnerability
Solution:
Gentoo has released an advisory to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-p2p/opendchub-0.7.14-r2"
Solution:
Gentoo has released an advisory to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-p2p/opendchub-0.7.14-r2"
References
Open DC Hub Remote Buffer Overflow Vulnerability
References:
References:
- Open DC Hub Homepage (Open DC Hub)
- Buffer Overflow in Open Dc Hub 0.7.14 ("Donato Ferrante"
)