Bidwatcher Remote Format String Vulnerability
BID:12590
Info
Bidwatcher Remote Format String Vulnerability
| Bugtraq ID: | 12590 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0158 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Ulf Harnhammar is credited with the discovery of this issue. |
| Vulnerable: |
Gentoo Linux bidwatcher bidwatcher 1.3.16 bidwatcher bidwatcher 1.3.15 bidwatcher bidwatcher 1.3.14 bidwatcher bidwatcher 1.3.13 bidwatcher bidwatcher 1.3.12 bidwatcher bidwatcher 1.3.11 bidwatcher bidwatcher 1.3.10 bidwatcher bidwatcher 1.3.9 bidwatcher bidwatcher 1.3.8 bidwatcher bidwatcher 1.3.7 bidwatcher bidwatcher 1.3.6 bidwatcher bidwatcher 1.3.5 bidwatcher bidwatcher 1.3.4 bidwatcher bidwatcher 1.3.3 bidwatcher bidwatcher 1.3.2 bidwatcher bidwatcher 1.3.1 bidwatcher bidwatcher 1.3 |
| Not Vulnerable: |
bidwatcher bidwatcher 1.3.17 |
Discussion
Bidwatcher Remote Format String Vulnerability
A remote format string vulnerability affects bidwatcher. This issue is due to a failure of the application to properly implement a formatted string function.
An attacker may leverage this issue to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
A remote format string vulnerability affects bidwatcher. This issue is due to a failure of the application to properly implement a formatted string function.
An attacker may leverage this issue to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
Bidwatcher Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Bidwatcher Remote Format String Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Debian Linux has released advisory DSA 687-1 along with fixes dealing with this issue. For more information, please see the referenced advisory.
Gentoo has released an advisory (GLSA 200503-06) and an updated eBuild to address this vulnerability. Gentoo users that are running the affected software may apply the update by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/bidwatcher-1.13.17"
bidwatcher bidwatcher 1.3
bidwatcher bidwatcher 1.3.1
bidwatcher bidwatcher 1.3.10
bidwatcher bidwatcher 1.3.11
bidwatcher bidwatcher 1.3.12
bidwatcher bidwatcher 1.3.13
bidwatcher bidwatcher 1.3.14
bidwatcher bidwatcher 1.3.15
bidwatcher bidwatcher 1.3.16
bidwatcher bidwatcher 1.3.2
bidwatcher bidwatcher 1.3.3
bidwatcher bidwatcher 1.3.4
bidwatcher bidwatcher 1.3.5
bidwatcher bidwatcher 1.3.6
bidwatcher bidwatcher 1.3.7
bidwatcher bidwatcher 1.3.8
bidwatcher bidwatcher 1.3.9
Solution:
The vendor has released an upgrade dealing with this issue.
Debian Linux has released advisory DSA 687-1 along with fixes dealing with this issue. For more information, please see the referenced advisory.
Gentoo has released an advisory (GLSA 200503-06) and an updated eBuild to address this vulnerability. Gentoo users that are running the affected software may apply the update by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/bidwatcher-1.13.17"
bidwatcher bidwatcher 1.3
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.1
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.10
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.11
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.12
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.13
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.14
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.15
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.16
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.2
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.3
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz -
Debian bidwatcher_1.3.3-1woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_alpha.deb -
Debian bidwatcher_1.3.3-1woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_arm.deb -
Debian bidwatcher_1.3.3-1woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_hppa.deb -
Debian bidwatcher_1.3.3-1woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_i386.deb -
Debian bidwatcher_1.3.3-1woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_ia64.deb -
Debian bidwatcher_1.3.3-1woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_m68k.deb -
Debian bidwatcher_1.3.3-1woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_mips.deb -
Debian bidwatcher_1.3.3-1woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_mipsel.deb -
Debian bidwatcher_1.3.3-1woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_powerpc.deb -
Debian bidwatcher_1.3.3-1woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_s390.deb -
Debian bidwatcher_1.3.3-1woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bidwatcher/bidwatcher_1 .3.3-1woody1_sparc.deb
bidwatcher bidwatcher 1.3.4
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.5
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.6
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.7
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.8
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz
bidwatcher bidwatcher 1.3.9
-
bidwatcher bidwatcher 1.3.17
http://prdownloads.sourceforge.net/bidwatcher/bidwatcher-1.3.17.tar.gz