ELOG Web Logbook Attached Filename Remote Buffer Overflow Vulnerability
BID:12639
Info
ELOG Web Logbook Attached Filename Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 12639 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2005 12:00AM |
| Updated: | Feb 23 2005 12:00AM |
| Credit: | Discovery of this vulnerability is credited to nrktx. |
| Vulnerable: |
Elog Web Logbook Elog Web Logbook 2.5.6 Elog Web Logbook Elog Web Logbook 2.5 Elog Web Logbook Elog Web Logbook 2.4 Elog Web Logbook Elog Web Logbook 2.2.4 Elog Web Logbook Elog Web Logbook 2.2.3 Elog Web Logbook Elog Web Logbook 2.2.2 Elog Web Logbook Elog Web Logbook 2.2.1 Elog Web Logbook Elog Web Logbook 2.2 .0 Elog Web Logbook Elog Web Logbook 2.1.3 Elog Web Logbook Elog Web Logbook 2.1.2 Elog Web Logbook Elog Web Logbook 2.1.1 Elog Web Logbook Elog Web Logbook 2.1 .0 Elog Web Logbook Elog Web Logbook 2.0.5 Elog Web Logbook Elog Web Logbook 2.0.4 Elog Web Logbook Elog Web Logbook 2.0.3 Elog Web Logbook Elog Web Logbook 2.0.2 Elog Web Logbook Elog Web Logbook 2.0.1 Elog Web Logbook Elog Web Logbook 2.0 .0 |
| Not Vulnerable: | |
Discussion
ELOG Web Logbook Attached Filename Remote Buffer Overflow Vulnerability
ELOG Web Logbook is prone to a remote buffer overflow vulnerability. The vulnerability is reported to exist due to a lack of sufficient boundary checks performed on user-supplied data.
A remote attacker that can authenticate to the affected daemon may leverage this issue to execute arbitrary instructions in the context of the affected daemon.
This vulnerability is reported to affect ELOG versions up to and including version 2.5.6.
ELOG Web Logbook is prone to a remote buffer overflow vulnerability. The vulnerability is reported to exist due to a lack of sufficient boundary checks performed on user-supplied data.
A remote attacker that can authenticate to the affected daemon may leverage this issue to execute arbitrary instructions in the context of the affected daemon.
This vulnerability is reported to affect ELOG versions up to and including version 2.5.6.
Exploit / POC
ELOG Web Logbook Attached Filename Remote Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
ELOG Web Logbook Attached Filename Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ELOG Web Logbook Attached Filename Remote Buffer Overflow Vulnerability
References:
References:
- Elog Web Logbook Homepage (Elog Web Logbook)