NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
BID:18525
CVE-2006-3145 |Info
NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
| Bugtraq ID: | 18525 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2006 12:00AM |
| Updated: | Jun 23 2006 04:20PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Netpbm Netpbm 10.33 Netpbm Netpbm 10.32 Netpbm Netpbm 10.31 Netpbm Netpbm 10.30 |
| Not Vulnerable: |
Netpbm Netpbm 10.34 |
Discussion
NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
Netpbm 'pnmtofits' is prone to an off-by-one buffer-overflow vulnerability.
The issue presents itself when the application processes a malicious file. A remote attacker may exploit this issue to trigger a denial-of-service condition. The attacker might also be able to execute arbitrary code, but this has not been confirmed.
Netpbm versions 10.30 to 10.33 are vulnerable to this issue.
Netpbm 'pnmtofits' is prone to an off-by-one buffer-overflow vulnerability.
The issue presents itself when the application processes a malicious file. A remote attacker may exploit this issue to trigger a denial-of-service condition. The attacker might also be able to execute arbitrary code, but this has not been confirmed.
Netpbm versions 10.30 to 10.33 are vulnerable to this issue.
Exploit / POC
NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
Solution:
The vendor has released version 10.34 to address this issue. Please see the references for more information and vendor advisories.
Netpbm Netpbm 10.31
Netpbm Netpbm 10.32
Netpbm Netpbm 10.33
Netpbm Netpbm 10.30
Solution:
The vendor has released version 10.34 to address this issue. Please see the references for more information and vendor advisories.
Netpbm Netpbm 10.31
-
Netpbm Netpbm 10.34
http://sourceforge.net/project/showfiles.php?group_id=5128&package_id= 6492&release_id=425769
Netpbm Netpbm 10.32
-
Netpbm Netpbm 10.34
http://sourceforge.net/project/showfiles.php?group_id=5128&package_id= 6492&release_id=425769
Netpbm Netpbm 10.33
-
Netpbm Netpbm 10.34
http://sourceforge.net/project/showfiles.php?group_id=5128&package_id= 6492&release_id=425769
Netpbm Netpbm 10.30
References
NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
References:
References:
- Netpbm Homepage (Netpbm)
- Release Name: 10.34 (Netpbm)