Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
BID:16467
Info
Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
| Bugtraq ID: | 16467 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 01 2006 12:00AM |
| Updated: | Feb 07 2006 08:56PM |
| Credit: | Adam Zabrocki <[email protected]> discovered this issue. |
| Vulnerable: |
Fcron Fcron 3.0 |
| Not Vulnerable: | |
Discussion
Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
Fcron is susceptible to a local buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This issue allows local attackers to execute arbitrary machine code with superuser privileges, since the affected utility is installed setuid-superuser by default in some installations. This allows attackers to completely compromise affected computers.
Fcron version 3.0 is affected by this issue; previous versions may also be affected.
Update: This issue is now retired. Further analysis reveals that this issue cannot be exploited for code execution; therefore, this is not a vulnerability.
Fcron is susceptible to a local buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This issue allows local attackers to execute arbitrary machine code with superuser privileges, since the affected utility is installed setuid-superuser by default in some installations. This allows attackers to completely compromise affected computers.
Fcron version 3.0 is affected by this issue; previous versions may also be affected.
Update: This issue is now retired. Further analysis reveals that this issue cannot be exploited for code execution; therefore, this is not a vulnerability.
Exploit / POC
Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
A proof of concept command to demonstrate this issue was provided:
convert-fcrontab `perl -e 'print "pi3"x600'`
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
A proof of concept command to demonstrate this issue was provided:
convert-fcrontab `perl -e 'print "pi3"x600'`
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
References:
References: