AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
BID:18859
CVE-2006-3581 | CVE-2006-3582 |Info
AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
| Bugtraq ID: | 18859 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3581 CVE-2006-3582 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2006 12:00AM |
| Updated: | Sep 12 2006 11:12PM |
| Credit: | Discovery is credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Gentoo Linux Audacious Audacious 1.0 AdPlug AdPlug 2.0 |
| Not Vulnerable: |
Audacious Audacious 1.1 |
Discussion
AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
The AdPlug library is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the library's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running applications that use the affected library to open attacker-supplied malicious files.
The AdPlug library version 2.0 is vulnerable to these issues; previous versions may also be affected.
The AdPlug library is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the library's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running applications that use the affected library to open attacker-supplied malicious files.
The AdPlug library version 2.0 is vulnerable to these issues; previous versions may also be affected.
Exploit / POC
AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept code may be used to demonstrate several of these issues by crashing the affected library:
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept code may be used to demonstrate several of these issues by crashing the affected library:
Solution / Fix
AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
Solution:
The vendor has committed fixes to their CVS repository as of July 5, 2006. Official fix packages are not currently known to be available.
Please see the referenced advisories for more information.
Solution:
The vendor has committed fixes to their CVS repository as of July 5, 2006. Official fix packages are not currently known to be available.
Please see the referenced advisories for more information.
References
AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
References:
References:
- AdPlug Home Page (AdPlug)
- AdPlug NEWS (AdPlug)
- Various heap and stack overflow bugs in AdPlug library 2.0 (CVS 04 Jul 2006) (Luigi Auriemma
)