PCAL Calendar File getline Buffer Overflow Vulnerability
BID:12035
Info
PCAL Calendar File getline Buffer Overflow Vulnerability
| Bugtraq ID: | 12035 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1289 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery is credited to Danny Lungstrom. |
| Vulnerable: |
PCAL PCAL 4.7.1 PCAL PCAL 4.7 .0 PCAL PCAL 4.6 .0 PCAL PCAL 4.5 .0 PCAL PCAL 4.3 .0 PCAL PCAL 4.1 .0 |
| Not Vulnerable: |
PCAL PCAL 4.8 .0 |
Discussion
PCAL Calendar File getline Buffer Overflow Vulnerability
PCAL is prone to a buffer overflow vulnerability. This issue is exposed when the application handles a calendar file that contains excessively long lines. Since calendar files may originate from an external or untrusted source, this vulnerability is considered to be remote in nature.
Successful exploitation of this issue will result in execution of arbitrary code as the user of the application.
PCAL is prone to a buffer overflow vulnerability. This issue is exposed when the application handles a calendar file that contains excessively long lines. Since calendar files may originate from an external or untrusted source, this vulnerability is considered to be remote in nature.
Successful exploitation of this issue will result in execution of arbitrary code as the user of the application.
Exploit / POC
PCAL Calendar File getline Buffer Overflow Vulnerability
The following exploit example has been published:
The following exploit example has been published:
Solution / Fix
PCAL Calendar File getline Buffer Overflow Vulnerability
Solution:
Debian has released advisory DSA 625-1 to address this issue. Please see the attached advisory for further information on obtaining and applying fixes.
The vendor has addressed this vulnerability in PCAL 4.8.0.
PCAL PCAL 4.1 .0
PCAL PCAL 4.3 .0
PCAL PCAL 4.5 .0
PCAL PCAL 4.6 .0
PCAL PCAL 4.7 .0
PCAL PCAL 4.7.1
Solution:
Debian has released advisory DSA 625-1 to address this issue. Please see the attached advisory for further information on obtaining and applying fixes.
The vendor has addressed this vulnerability in PCAL 4.8.0.
PCAL PCAL 4.1 .0
-
PCAL PCAL 4.8.0
http://sourceforge.net/project/showfiles.php?group_id=99004
PCAL PCAL 4.3 .0
-
PCAL PCAL 4.8.0
http://sourceforge.net/project/showfiles.php?group_id=99004
PCAL PCAL 4.5 .0
-
PCAL PCAL 4.8.0
http://sourceforge.net/project/showfiles.php?group_id=99004
PCAL PCAL 4.6 .0
-
PCAL PCAL 4.8.0
http://sourceforge.net/project/showfiles.php?group_id=99004
PCAL PCAL 4.7 .0
-
Debian pcal_4.7-8woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_a lpha.deb -
Debian pcal_4.7-8woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_a rm.deb -
Debian pcal_4.7-8woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_h ppa.deb -
Debian pcal_4.7-8woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_i 386.deb -
Debian pcal_4.7-8woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_i a64.deb -
Debian pcal_4.7-8woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_m 68k.deb -
Debian pcal_4.7-8woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_m ips.deb -
Debian pcal_4.7-8woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_m ipsel.deb -
Debian pcal_4.7-8woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_p owerpc.deb -
Debian pcal_4.7-8woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_s 390.deb -
Debian pcal_4.7-8woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pcal/pcal_4.7-8woody1_s parc.deb -
PCAL PCAL 4.8.0
http://sourceforge.net/project/showfiles.php?group_id=99004
PCAL PCAL 4.7.1
-
PCAL PCAL 4.8.0
http://sourceforge.net/project/showfiles.php?group_id=99004
References
PCAL Calendar File getline Buffer Overflow Vulnerability
References:
References:
- [remote] [control] pcal 4.7.1 getline overflows tmpbuf; get_holiday overflows tm ("D. J. Bernstein"
) - PCAL and LCAL Homepage (PCAL)