Zoo Misc.c Buffer Overflow Vulnerability
BID:16790
Info
Zoo Misc.c Buffer Overflow Vulnerability
| Bugtraq ID: | 16790 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0855 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2006 12:00AM |
| Updated: | Dec 12 2006 09:33PM |
| Credit: | Jean-Sebastien Guay-Leroux is credited with the discovery of this vulnerability. |
| Vulnerable: |
Zoo Zoo 2.10 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 Slackware Linux 10.2 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Barracuda Barracuda Spam Firewall 3.1.18 firmware Barracuda Barracuda Spam Firewall 3.1.17 firmware |
| Not Vulnerable: |
Barracuda Barracuda Spam Firewall 3.3.03.022 firmware |
Discussion
Zoo Misc.c Buffer Overflow Vulnerability
Zoo is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application.
Zoo is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application.
Exploit / POC
Zoo Misc.c Buffer Overflow Vulnerability
This vulnerability can be tested using the PIRANA exploitation framework available at the following location:
http://www.guay-leroux.com/projects/pirana-0.2.1.tar.gz
This vulnerability can be tested using the PIRANA exploitation framework available at the following location:
http://www.guay-leroux.com/projects/pirana-0.2.1.tar.gz
Solution / Fix
Zoo Misc.c Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Please see the referenced vendor advisories for more information and fixes.
Zoo Zoo 2.10
Slackware Linux 10.2
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Please see the referenced vendor advisories for more information and fixes.
Zoo Zoo 2.10
-
Debian zoo_2.10-11sarge0_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_a lpha.deb -
Debian zoo_2.10-11sarge0_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_a md64.deb -
Debian zoo_2.10-11sarge0_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_a rm.deb -
Debian zoo_2.10-11sarge0_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_h ppa.deb -
Debian zoo_2.10-11sarge0_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_i 386.deb -
Debian zoo_2.10-11sarge0_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_i a64.deb -
Debian zoo_2.10-11sarge0_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_m 68k.deb -
Debian zoo_2.10-11sarge0_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_m ips.deb -
Debian zoo_2.10-11sarge0_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_m ipsel.deb -
Debian zoo_2.10-11sarge0_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_p owerpc.deb -
Debian zoo_2.10-11sarge0_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_s 390.deb -
Debian zoo_2.10-11sarge0_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zoo/zoo_2.10-11sarge0_s parc.deb -
Debian zoo_2.10-9woody0_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_alpha.deb -
Debian zoo_2.10-9woody0_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_arm.deb -
Debian zoo_2.10-9woody0_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_hppa.deb -
Debian zoo_2.10-9woody0_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_i386.deb -
Debian zoo_2.10-9woody0_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_ia64.deb -
Debian zoo_2.10-9woody0_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_m68k.deb -
Debian zoo_2.10-9woody0_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_mips.deb -
Debian zoo_2.10-9woody0_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_mipsel.deb -
Debian zoo_2.10-9woody0_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_powerpc.deb -
Debian zoo_2.10-9woody0_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_s390.deb -
Debian zoo_2.10-9woody0_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/z/zoo/zoo_2.10-9woody 0_sparc.deb -
Slackware bin-10.2-i486-2_10.2.tgz
Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ bin-10.2-i486-2_10.2.tgz
Slackware Linux 10.2
-
Slackware bin-10.2-i486-2_10.2.tgz
Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ bin-10.2-i486-2_10.2.tgz
References
Zoo Misc.c Buffer Overflow Vulnerability
References:
References:
- Barracuda Spam Firewall Product Page (Barracuda Networks)
- GNU tar Homepage (GNU)
- zoo contains exploitable buffer overflows (Jean-Sébastien Guay-Leroux)
- Barracuda ZOO archiver security bug leads to remote compromise ( =?ISO-8859-1?Q?Jean-S=E9bastien_Guay-Leroux?=
)