Tin News Reader Buffer Overflow Vulnerability
BID:16728
Info
Tin News Reader Buffer Overflow Vulnerability
| Bugtraq ID: | 16728 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0804 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2006 12:00AM |
| Updated: | Nov 24 2006 03:40PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Tin News Reader 1.8 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. blam 9.3 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.4 OpenPKG OpenPKG 2.3 OpenPKG OpenPKG Current Gentoo Linux |
| Not Vulnerable: |
Tin News Reader 1.8.1 |
Discussion
Tin News Reader Buffer Overflow Vulnerability
The Tin news reader is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper boundary checks on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code on the victim userâ??s computer in the context of the victim user. This may facilitate a compromise of the affected computer.
Versions 1.8.0 and earlier are vulnerable.
The Tin news reader is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper boundary checks on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code on the victim userâ??s computer in the context of the victim user. This may facilitate a compromise of the affected computer.
Versions 1.8.0 and earlier are vulnerable.
Exploit / POC
Tin News Reader Buffer Overflow Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Tin News Reader Buffer Overflow Vulnerability
Solution:
Tin version 1.8.1 is available; please see the reference section for further details.
Please see the references for further information and fixes.
Tin News Reader 1.8
Solution:
Tin version 1.8.1 is available; please see the reference section for further details.
Please see the references for further information and fixes.
Tin News Reader 1.8
-
Tin tin-current.tar.gz
ftp://ftp.tin.org/pub/news/clients/tin/stable/tin-current.tar.gz
References
Tin News Reader Buffer Overflow Vulnerability
References:
References: