LinPopUp Remote Buffer Overflow Vulnerability
BID:11997
Info
LinPopUp Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11997 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1282 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery is credited to Stephen Dranger. |
| Vulnerable: |
LinPopUp LinPopUp 1.2 Gentoo Linux |
| Not Vulnerable: | |
Discussion
LinPopUp Remote Buffer Overflow Vulnerability
LinPopUp is reported prone to a remote buffer overflow vulnerability. This issue arises because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers. It is reported that this issue can allow an attacker to gain unauthorized access to a computer in the context of the application.
An attacker can exploit this issue by crafting a malicious message that contains excessive string data, replacement memory addresses, and executable instructions to trigger this issue.
LinPopUp version 1.2.0 is reported prone to this vulnerability. It is likely that other versions are affected as well.
LinPopUp is reported prone to a remote buffer overflow vulnerability. This issue arises because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers. It is reported that this issue can allow an attacker to gain unauthorized access to a computer in the context of the application.
An attacker can exploit this issue by crafting a malicious message that contains excessive string data, replacement memory addresses, and executable instructions to trigger this issue.
LinPopUp version 1.2.0 is reported prone to this vulnerability. It is likely that other versions are affected as well.
Exploit / POC
LinPopUp Remote Buffer Overflow Vulnerability
A proof of concept exploit is available. This has not been verified by Symantec:
A proof of concept exploit is available. This has not been verified by Symantec:
Solution / Fix
LinPopUp Remote Buffer Overflow Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200501-01 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-im/linpopup-2.0.4-r1"
Please see the referenced advisory for further information.
Debian has released advisory DSA 632-1 to provide updates that address this vulnerability. Please see the attached advisory for further information on obtaining and applying updates.
LinPopUp LinPopUp 1.2
Solution:
Gentoo Linux has released advisory GLSA 200501-01 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-im/linpopup-2.0.4-r1"
Please see the referenced advisory for further information.
Debian has released advisory DSA 632-1 to provide updates that address this vulnerability. Please see the attached advisory for further information on obtaining and applying updates.
LinPopUp LinPopUp 1.2
-
Debian linpopup_1.2.0-2woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_alpha.deb -
Debian linpopup_1.2.0-2woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_arm.deb -
Debian linpopup_1.2.0-2woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_hppa.deb -
Debian linpopup_1.2.0-2woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_i386.deb -
Debian linpopup_1.2.0-2woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_ia64.deb -
Debian linpopup_1.2.0-2woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_m68k.deb -
Debian linpopup_1.2.0-2woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_mips.deb -
Debian linpopup_1.2.0-2woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_mipsel.deb -
Debian linpopup_1.2.0-2woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_powerpc.deb -
Debian linpopup_1.2.0-2woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_s390.deb -
Debian linpopup_1.2.0-2woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/linpopup/linpopup_1.2.0 -2woody1_sparc.deb
References
LinPopUp Remote Buffer Overflow Vulnerability
References:
References:
- [remote] [control] LinPopUp 1.2.0 overflows sub_string buffer ("D. J. Bernstein"
) - LinPopUp Product Page (LinPopUp)