ProZilla Buffer Overflow Vulnerability
BID:14993
Info
ProZilla Buffer Overflow Vulnerability
| Bugtraq ID: | 14993 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2961 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovered by Tavis Ormandy. |
| Vulnerable: |
Prozilla ProZilla Download Accelerator 1.3.7 .4 Prozilla ProZilla Download Accelerator 1.3.6 Prozilla ProZilla Download Accelerator 1.3.5 .2 Prozilla ProZilla Download Accelerator 1.3.5 .1 Prozilla ProZilla Download Accelerator 1.3.5 Prozilla ProZilla Download Accelerator 1.3.4 Prozilla ProZilla Download Accelerator 1.3.3 .x Prozilla ProZilla Download Accelerator 1.3.3 Prozilla ProZilla Download Accelerator 1.3.2 Prozilla ProZilla Download Accelerator 1.3.1 Prozilla ProZilla Download Accelerator 1.3 .0 Prozilla ProZilla Download Accelerator 1.0 x Prozilla ProZilla Download Accelerator 1.3.7.3 |
| Not Vulnerable: | |
Discussion
ProZilla Buffer Overflow Vulnerability
ProZilla is prone to a buffer overflow vulnerability. This issue is due to the failure of the application to properly bounds check user-supplied input prior to copying it to an insufficiently sized memory buffer.
Arbitrary code execution in the context of the user running the application is possible.
ProZilla is prone to a buffer overflow vulnerability. This issue is due to the failure of the application to properly bounds check user-supplied input prior to copying it to an insufficiently sized memory buffer.
Arbitrary code execution in the context of the user running the application is possible.
Exploit / POC
Solution / Fix
ProZilla Buffer Overflow Vulnerability
Solution:
Debian has released advisory DSA 834-1 and fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Prozilla ProZilla Download Accelerator 1.3.6
Solution:
Debian has released advisory DSA 834-1 and fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Prozilla ProZilla Download Accelerator 1.3.6
-
Debian prozilla_1.3.6-3woody3_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_alpha.deb -
Debian prozilla_1.3.6-3woody3_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_arm.deb -
Debian prozilla_1.3.6-3woody3_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_hppa.deb -
Debian prozilla_1.3.6-3woody3_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_i386.deb -
Debian prozilla_1.3.6-3woody3_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_ia64.deb -
Debian prozilla_1.3.6-3woody3_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_m68k.deb -
Debian prozilla_1.3.6-3woody3_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_mips.deb -
Debian prozilla_1.3.6-3woody3_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_mipsel.deb -
Debian prozilla_1.3.6-3woody3_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_powerpc.deb -
Debian prozilla_1.3.6-3woody3_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_s390.deb -
Debian prozilla_1.3.6-3woody3_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/prozilla/prozilla_1.3.6 -3woody3_sparc.deb
References
ProZilla Buffer Overflow Vulnerability
References:
References:
- [Prozilla] prozilla security bug report (Tavis Ormandy
) - ProZIlla Home Page (ProZIlla)