NCompress Decompress Buffer Underflow Vulnerability
BID:19455
Info
NCompress Decompress Buffer Underflow Vulnerability
| Bugtraq ID: | 19455 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-1168 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2006 12:00AM |
| Updated: | Dec 10 2013 12:56AM |
| Credit: | Tavis Ormandy discovered this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SGI Advanced Linux Environment 3.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 ncompress ncompress 4.2.4 ncompress ncompress 4.2.3 ncompress ncompress 4.2.2 ncompress ncompress 4.2.1 ncompress ncompress 4.1 ncompress ncompress 4.0 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 BusyBox BusyBox 1.18.5 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya S8710 R2.0.1 Avaya S8710 R2.0.0 Avaya S8710 CM 3.1 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8700 CM 3.1 Avaya S8500 0 Avaya S8300 0 Avaya Proactive Contact 5.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Avaya Integrated Management Avaya CVLAN Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya 96x1 IP Deskphone 6 |
| Not Vulnerable: | |
Discussion
NCompress Decompress Buffer Underflow Vulnerability
The ncompress utility is prone to a buffer-underflow vulnerability. When ncompress decompresses data, it fails to perform appropriate bounds checking, which may allow certain decompress operations to underflow an internal buffer. This may cause unpredictable effects on vulnerable systems.
Version 4.2.4 is reportedly vulnerable to this issue; earlier versions may be affected as well.
The ncompress utility is prone to a buffer-underflow vulnerability. When ncompress decompresses data, it fails to perform appropriate bounds checking, which may allow certain decompress operations to underflow an internal buffer. This may cause unpredictable effects on vulnerable systems.
Version 4.2.4 is reportedly vulnerable to this issue; earlier versions may be affected as well.
Exploit / POC
NCompress Decompress Buffer Underflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
NCompress Decompress Buffer Underflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
NCompress Decompress Buffer Underflow Vulnerability
References:
References:
- RHSA-2006:0663-13 - ncompress security update (Red Hat)
- root/archival/libarchive/decompress_uncompress.c (BusyBox)
- ASA-2011-337 Wind River Linux xmlsec, DHCP, freetype, Perl Security Update (WIND (Avaya)
- ASA-2012-117 busybox security and bug fix update (RHSA-2012-0308) (Avaya)
- Avaya Security Advisory ASA-2006-226 (Avaya)