ChBg Scenario File Overflow Vulnerability
BID:11957
Info
ChBg Scenario File Overflow Vulnerability
| Bugtraq ID: | 11957 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1264 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery is credited to Danny Lungstrom. |
| Vulnerable: |
ChBg ChBg 1.5.8 ChBg ChBg 1.5 |
| Not Vulnerable: | |
Discussion
ChBg Scenario File Overflow Vulnerability
ChBg is reported prone to a remote buffer overflow vulnerability. This issue arises because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers. It is reported that this issue can allow an attacker to gain superuser privileges on a vulnerable computer.
An attacker can exploit this issue by crafting a malicious scenario file. A scenario is a file containing a list of pictures to display.
If a user obtains this file and processes it through ChBg, the attacker-supplied instructions may be executed on the vulnerable computer.
ChBg 1.5 is reported prone to this vulnerability. It is likely that other versions are affected as well.
ChBg is reported prone to a remote buffer overflow vulnerability. This issue arises because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers. It is reported that this issue can allow an attacker to gain superuser privileges on a vulnerable computer.
An attacker can exploit this issue by crafting a malicious scenario file. A scenario is a file containing a list of pictures to display.
If a user obtains this file and processes it through ChBg, the attacker-supplied instructions may be executed on the vulnerable computer.
ChBg 1.5 is reported prone to this vulnerability. It is likely that other versions are affected as well.
Exploit / POC
ChBg Scenario File Overflow Vulnerability
A proof of concept file is available:
A proof of concept file is available:
Solution / Fix
ChBg Scenario File Overflow Vulnerability
Solution:
Debian has released an advisory DSA 644-1 to address this issue. Please see the referenced advisory for more information.
Mandrake Linux has made an advisory available (MDKSA-2005:027) dealing with this issue. Please see the referenced advisory for more information.
ChBg ChBg 1.5
Solution:
Debian has released an advisory DSA 644-1 to address this issue. Please see the referenced advisory for more information.
Mandrake Linux has made an advisory available (MDKSA-2005:027) dealing with this issue. Please see the referenced advisory for more information.
ChBg ChBg 1.5
-
Debian chbg_1.5-1woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_a lpha.deb -
Debian chbg_1.5-1woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_a rm.deb -
Debian chbg_1.5-1woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_i 386.deb -
Debian chbg_1.5-1woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_i a64.deb -
Debian chbg_1.5-1woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_m 68k.deb -
Debian chbg_1.5-1woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_m ips.deb -
Debian chbg_1.5-1woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_m ipsel.deb -
Debian chbg_1.5-1woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_p owerpc.deb -
Debian chbg_1.5-1woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_s 390.deb -
Debian chbg_1.5-1woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/chbg/chbg_1.5-1woody1_s parc.deb -
Mandrake chbg-1.5-8.1.100mdk.amd64.rpm
Mandrake Linux 10.0/amd64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake chbg-1.5-8.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake chbg-1.5-8.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake chbg-1.5-8.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake chbg-1.5-8.1.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake chbg-1.5-8.1.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php
References
ChBg Scenario File Overflow Vulnerability
References:
References:
- chbg 1.5 simplify_path overflows res buffer ("D. J. Bernstein"
) - ChBg Home Page (ChBg)