Peercast.org PeerCast Remote Format String Vulnerability
BID:13808
Info
Peercast.org PeerCast Remote Format String Vulnerability
| Bugtraq ID: | 13808 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1806 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to James Bercegay of the GulfTech Security Research Team. |
| Vulnerable: |
peercast.org PeerCast 0.1211 Gentoo Linux |
| Not Vulnerable: |
peercast.org PeerCast 0.1212 |
Discussion
Peercast.org PeerCast Remote Format String Vulnerability
PeerCast is affected by a remote format string vulnerability.
The vulnerability arises when the server attempts to handle a malformed HTTP GET request. A successful attack may result in crashing the server or lead to arbitrary code execution. This may facilitate unauthorized access.
PeerCast 0.1211 and prior versions are affected by this issue.
PeerCast is affected by a remote format string vulnerability.
The vulnerability arises when the server attempts to handle a malformed HTTP GET request. A successful attack may result in crashing the server or lead to arbitrary code execution. This may facilitate unauthorized access.
PeerCast 0.1211 and prior versions are affected by this issue.
Exploit / POC
Peercast.org PeerCast Remote Format String Vulnerability
Darkeagle <[email protected]> provided the 'p33r-b33r.c' proof of concept exploit.
[email protected] provided the 'peercast_format_string.c' proof of concept exploit.
Darkeagle <[email protected]> provided the 'p33r-b33r.c' proof of concept exploit.
[email protected] provided the 'peercast_format_string.c' proof of concept exploit.
Solution / Fix
Peercast.org PeerCast Remote Format String Vulnerability
Solution:
The vendor has released PeerCast 0.1212 to address this issue.
Gentoo Linux has released advisory GLSA 200506-15 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/peercast-0.1212"
Please see the referenced advisory for further information.
peercast.org PeerCast 0.1211
Solution:
The vendor has released PeerCast 0.1212 to address this issue.
Gentoo Linux has released advisory GLSA 200506-15 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/peercast-0.1212"
Please see the referenced advisory for further information.
peercast.org PeerCast 0.1211
-
peercast.org PeerCast v0.1212
http://www.peercast.org/download.php
References
Peercast.org PeerCast Remote Format String Vulnerability
References:
References:
- Important Security Update (peercast.org)
- PeerCast Homepage (peercast.org)
- Format String Vulnerability In Peercast 0.1211 And Earlier (GulfTech Security Research
)