Netkit RWho Packet Size Denial Of Service Vulnerability
BID:12524
Info
Netkit RWho Packet Size Denial Of Service Vulnerability
| Bugtraq ID: | 12524 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-1180 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Discovery is credited to Vlad902. |
| Vulnerable: |
Netkit Linux Netkit 0.17 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 |
| Not Vulnerable: | |
Discussion
Netkit RWho Packet Size Denial Of Service Vulnerability
The Netkit rwho daemon is prone to a denial of service vulnerability. This condition occurs when the server processes packets with malformed sizes.
The vulnerability is only reported to affect the software running on little endian platforms.
It is not known if this condition is due to a boundary condition error or if it may further be leveraged to execute arbitrary code.
The Netkit rwho daemon is prone to a denial of service vulnerability. This condition occurs when the server processes packets with malformed sizes.
The vulnerability is only reported to affect the software running on little endian platforms.
It is not known if this condition is due to a boundary condition error or if it may further be leveraged to execute arbitrary code.
Exploit / POC
Netkit RWho Packet Size Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Netkit RWho Packet Size Denial Of Service Vulnerability
Solution:
Debian has released advisory DSA 678-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Mandrake Linux has released advisory MDKSA-2005:039 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Netkit Linux Netkit 0.17
Solution:
Debian has released advisory DSA 678-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Mandrake Linux has released advisory MDKSA-2005:039 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Netkit Linux Netkit 0.17
-
Debian rwho_0.17-4woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_alpha.deb -
Debian rwho_0.17-4woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_arm.deb -
Debian rwho_0.17-4woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_hppa.deb -
Debian rwho_0.17-4woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_i386.deb -
Debian rwho_0.17-4woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_ia64.deb -
Debian rwho_0.17-4woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_m68k.deb -
Debian rwho_0.17-4woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_mips.deb -
Debian rwho_0.17-4woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_mipsel.deb -
Debian rwho_0.17-4woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_powerpc.deb -
Debian rwho_0.17-4woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_s390.deb -
Debian rwho_0.17-4woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwho_0.17-4 woody2_sparc.deb -
Debian rwhod_0.17-4woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_alpha.deb -
Debian rwhod_0.17-4woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_arm.deb -
Debian rwhod_0.17-4woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_hppa.deb -
Debian rwhod_0.17-4woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_i386.deb -
Debian rwhod_0.17-4woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_ia64.deb -
Debian rwhod_0.17-4woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_m68k.deb -
Debian rwhod_0.17-4woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_mips.deb -
Debian rwhod_0.17-4woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_mipsel.deb -
Debian rwhod_0.17-4woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_powerpc.deb -
Debian rwhod_0.17-4woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_s390.deb -
Debian rwhod_0.17-4woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/netkit-rwho/rwhod_0.17- 4woody2_sparc.deb -
Mandrake rwho-0.17-10.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rwho-0.17-10.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rwho-0.17-10.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rwho-0.17-10.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rwho-0.17-10.2.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rwho-0.17-10.2.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php