Mike Neuman OSH Command Line Argument Buffer Overflow Vulnerability
BID:12455
Info
Mike Neuman OSH Command Line Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 12455 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3533 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 05 2005 12:00AM |
| Updated: | Apr 25 2006 11:06PM |
| Credit: | Discovery of this vulnerability is credited to Charles Stevenson <[email protected]> |
| Vulnerable: |
osh osh 1.7 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Mike Neuman OSH Command Line Argument Buffer Overflow Vulnerability
A buffer overflow vulnerability is reported for osh when processing superfluous command line arguments. The problem likely occurs due to insufficient bounds checking when copying command line argument data into an internal memory buffer.
This buffer overflow may be exploited to execute arbitrary code with superuser privileges.
A buffer overflow vulnerability is reported for osh when processing superfluous command line arguments. The problem likely occurs due to insufficient bounds checking when copying command line argument data into an internal memory buffer.
This buffer overflow may be exploited to execute arbitrary code with superuser privileges.
Exploit / POC
Mike Neuman OSH Command Line Argument Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Mike Neuman OSH Command Line Argument Buffer Overflow Vulnerability
Solution:
Debian GNU/Linux has released advisory DSA 918-1, along with fixes to address various issues in OSH. Please see the referenced advisory for further information.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
osh osh 1.7
Solution:
Debian GNU/Linux has released advisory DSA 918-1, along with fixes to address various issues in OSH. Please see the referenced advisory for further information.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
osh osh 1.7
-
Debian osh_1.7-11woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_ar m.deb -
Debian osh_1.7-11woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_hp pa.deb -
Debian osh_1.7-11woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_i3 86.deb -
Debian osh_1.7-11woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_ia 64.deb -
Debian osh_1.7-11woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_m6 8k.deb -
Debian osh_1.7-11woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_mi ps.deb -
Debian osh_1.7-11woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_mi psel.deb -
Debian osh_1.7-11woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_po werpc.deb -
Debian osh_1.7-11woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_s3 90.deb -
Debian osh_1.7-11woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_sp arc.deb -
Debian osh_1.7-13sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_al pha.deb -
Debian osh_1.7-13sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_am d64.deb -
Debian osh_1.7-13sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_ar m.deb -
Debian osh_1.7-13sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_i3 86.deb -
Debian osh_1.7-13sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_s3 90.deb -
Debian osh_1.7-11woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_al pha.deb -
Debian osh_1.7-11woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_ar m.deb -
Debian osh_1.7-11woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_hp pa.deb -
Debian osh_1.7-11woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_i3 86.deb -
Debian osh_1.7-11woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_ia 64.deb -
Debian osh_1.7-11woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_m6 8k.deb -
Debian osh_1.7-11woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_mi ps.deb -
Debian osh_1.7-11woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_mi psel.deb -
Debian osh_1.7-11woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_po werpc.deb -
Debian osh_1.7-11woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_s3 90.deb -
Debian osh_1.7-11woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-11woody2_sp arc.deb -
Debian osh_1.7-13sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_al pha.deb -
Debian osh_1.7-13sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_am d64.deb -
Debian osh_1.7-13sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_ar m.deb -
Debian osh_1.7-13sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_hp pa.deb -
Debian osh_1.7-13sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_i3 86.deb -
Debian osh_1.7-13sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_ia 64.deb -
Debian osh_1.7-13sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_m6 8k.deb -
Debian osh_1.7-13sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_mi ps.deb -
Debian osh_1.7-13sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_mi psel.deb -
Debian osh_1.7-13sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_po werpc.deb -
Debian osh_1.7-13sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_s3 90.deb -
Debian osh_1.7-13sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/osh/osh_1.7-13sarge1_sp arc.deb