Network Block Device Server Buffer Overflow Vulnerability
BID:16029
Info
Network Block Device Server Buffer Overflow Vulnerability
| Bugtraq ID: | 16029 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3534 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2005 12:00AM |
| Updated: | May 23 2006 10:48PM |
| Credit: | Kurt Fitzner is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Personal 10.0 OSS Network Block Device NBD 2.8.2 Network Block Device NBD 2.8.1 Network Block Device NBD 2.8 Network Block Device NBD 2.7.5 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
Network Block Device NBD 2.8.3 Network Block Device NBD 2.7.6 |
Discussion
Network Block Device Server Buffer Overflow Vulnerability
NBD is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the server to do proper bounds checking on user-supplied data before using it in finite-sized buffers.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the underlying system.
NBD is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the server to do proper bounds checking on user-supplied data before using it in finite-sized buffers.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the underlying system.
Exploit / POC
Network Block Device Server Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Network Block Device Server Buffer Overflow Vulnerability
Solution:
The vendor has released NBD versions 2.7.6 and 2.8.3 to address this issue.
Please see the referenced advisories for further information.
Network Block Device NBD 2.7.5
Network Block Device NBD 2.8
Network Block Device NBD 2.8.1
Network Block Device NBD 2.8.2
Solution:
The vendor has released NBD versions 2.7.6 and 2.8.3 to address this issue.
Please see the referenced advisories for further information.
Network Block Device NBD 2.7.5
-
Network Block Device nbd-2.7.6.tar.bz2
http://prdownloads.sourceforge.net/nbd/nbd-2.7.6.tar.bz2?download
Network Block Device NBD 2.8
-
Network Block Device nbd-2.8.3.tar.bz2
http://prdownloads.sourceforge.net/nbd/nbd-2.8.3.tar.bz2?download
Network Block Device NBD 2.8.1
-
Network Block Device nbd-2.8.3.tar.bz2
http://prdownloads.sourceforge.net/nbd/nbd-2.8.3.tar.bz2?download
Network Block Device NBD 2.8.2
-
Network Block Device nbd-2.8.3.tar.bz2
http://prdownloads.sourceforge.net/nbd/nbd-2.8.3.tar.bz2?download
References
Network Block Device Server Buffer Overflow Vulnerability
References:
References:
- Buffer overwrite bug in nbd-server (Kurt Fitzner)
- NBD Homepage (Network Block Device)