UMN Gopherd 2.x Remote Root Buffer Overflow Vulnerability
BID:1569
Info
UMN Gopherd 2.x Remote Root Buffer Overflow Vulnerability
| Bugtraq ID: | 1569 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 10 2000 12:00AM |
| Updated: | Aug 10 2000 12:00AM |
| Credit: | Disclosed in an advisory by Guardent (A0208102000) on August 10, 2000. |
| Vulnerable: |
University of Minnesota gopherd 2.3.1 University of Minnesota gopherd 2.3 |
| Not Vulnerable: | |
Discussion
UMN Gopherd 2.x Remote Root Buffer Overflow Vulnerability
There is a buffer overflow vulnerability in gopherd 2.x versions (by University of Minnesota) which could result in a remote root compromise of a targetted host. The problem lies in the generation of a Gopher DES Key (GDESKey), done by gopherd when the server receives an instruction to decode a ticket of the form "* [username] [ticket]" from a client.
There is a buffer overflow vulnerability in gopherd 2.x versions (by University of Minnesota) which could result in a remote root compromise of a targetted host. The problem lies in the generation of a Gopher DES Key (GDESKey), done by gopherd when the server receives an instruction to decode a ticket of the form "* [username] [ticket]" from a client.
Exploit / POC
UMN Gopherd 2.x Remote Root Buffer Overflow Vulnerability
This vulnerability is exploitable, according to the advisory released by Guardent. Exploit code has not been received.
This vulnerability is exploitable, according to the advisory released by Guardent. Exploit code has not been received.
Solution / Fix
UMN Gopherd 2.x Remote Root Buffer Overflow Vulnerability
Solution:
The previous patch released by Guardent (gopherd2x.patch) patched the discussed vulnerability but introduced another buffer overflow condition. New patches are available.
University of Minnesota gopherd 2.3
University of Minnesota gopherd 2.3.1
Solution:
The previous patch released by Guardent (gopherd2x.patch) patched the discussed vulnerability but introduced another buffer overflow condition. New patches are available.
University of Minnesota gopherd 2.3
-
Guardent gopherd2.3.patch
http://www.securityfocus.com/data/vulnerabilities/patches/gopherd2.3.p atch
University of Minnesota gopherd 2.3.1
-
Guardent gopherd2.3.1.patch
http://www.securityfocus.com/data/vulnerabilities/patches/gopherd2.3.1 .patch
References
UMN Gopherd 2.x Remote Root Buffer Overflow Vulnerability
References:
References: