NapShare Remote Buffer Overflow Vulnerability
BID:11967
Info
NapShare Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11967 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Bartlomiej Sieka discovered this vulnerability. |
| Vulnerable: |
NapShare NapShare 1.2 |
| Not Vulnerable: | |
Discussion
NapShare Remote Buffer Overflow Vulnerability
It is reported that NapShare is susceptible to a remote buffer overflow vulnerability. This is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed-size memory buffer.
Attackers running malicious Gnutella servers are reportedly able to exploit this vulnerability to execute arbitrary code in the context of the vulnerable application.
Version 1.2 of NapShare is reported susceptible. Other versions may also be affected.
It is reported that NapShare is susceptible to a remote buffer overflow vulnerability. This is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed-size memory buffer.
Attackers running malicious Gnutella servers are reportedly able to exploit this vulnerability to execute arbitrary code in the context of the vulnerable application.
Version 1.2 of NapShare is reported susceptible. Other versions may also be affected.
Exploit / POC
NapShare Remote Buffer Overflow Vulnerability
Proof of concept exploits have been provided:
Proof of concept exploits have been provided:
Solution / Fix
NapShare Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
NapShare Remote Buffer Overflow Vulnerability
References:
References:
- [remote] [control] NapShare 1.2 auto_filter_extern overflows filename buffer ("D. J. Bernstein"
) - NapShare Home Page (NapShare)