ELOG Web Logbook Multiple Remote Buffer Overflow Vulnerabilities
BID:15932
Info
ELOG Web Logbook Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 15932 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 13 2006 08:33PM |
| Credit: | Discovery of this vulnerability is credited to "GroundZero Security" <[email protected]>. |
| Vulnerable: |
Elog Web Logbook Elog Web Logbook 2.6 .0 Elog Web Logbook Elog Web Logbook 2.5.6 Elog Web Logbook Elog Web Logbook 2.5 Elog Web Logbook Elog Web Logbook 2.4 Elog Web Logbook Elog Web Logbook 2.2.4 Elog Web Logbook Elog Web Logbook 2.2.3 Elog Web Logbook Elog Web Logbook 2.2.2 Elog Web Logbook Elog Web Logbook 2.2.1 Elog Web Logbook Elog Web Logbook 2.2 .0 Elog Web Logbook Elog Web Logbook 2.1.3 Elog Web Logbook Elog Web Logbook 2.1.2 Elog Web Logbook Elog Web Logbook 2.1.1 Elog Web Logbook Elog Web Logbook 2.1 .0 Elog Web Logbook Elog Web Logbook 2.0.5 Elog Web Logbook Elog Web Logbook 2.0.4 Elog Web Logbook Elog Web Logbook 2.0.3 Elog Web Logbook Elog Web Logbook 2.0.2 Elog Web Logbook Elog Web Logbook 2.0.1 Elog Web Logbook Elog Web Logbook 2.0 .0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
ELOG Web Logbook Multiple Remote Buffer Overflow Vulnerabilities
ELOG Web Logbook is prone to two remote buffer overflow vulnerabilities. The application fails to perform sufficient boundary checks on user-supplied data.
These issues allow remote attackers to execute arbitrary machine code in the context of the vulnerable server process.
This issue affects version 2.6.0. Prior versions may also be affected.
ELOG Web Logbook is prone to two remote buffer overflow vulnerabilities. The application fails to perform sufficient boundary checks on user-supplied data.
These issues allow remote attackers to execute arbitrary machine code in the context of the vulnerable server process.
This issue affects version 2.6.0. Prior versions may also be affected.
Exploit / POC
ELOG Web Logbook Multiple Remote Buffer Overflow Vulnerabilities
Example URIs sufficient to crash affected server processes are available:
http://www.example.com/?select=1&mode=AAAAAAAAAAAAAAAAAAAAAAAAAAAAA<lots more>
http://www.example.com/?cmd=AAAAAAAAAAAAAAAAAAAAAAAAAAAAA<lots more>
--
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Example URIs sufficient to crash affected server processes are available:
http://www.example.com/?select=1&mode=AAAAAAAAAAAAAAAAAAAAAAAAAAAAA<lots more>
http://www.example.com/?cmd=AAAAAAAAAAAAAAAAAAAAAAAAAAAAA<lots more>
--
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ELOG Web Logbook Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Debian Linux has released an advisory to address this issue. Please see the referenced vendor advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian Linux has released an advisory to address this issue. Please see the referenced vendor advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ELOG Web Logbook Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- Elog Web Logbook Homepage (Elog Web Logbook)