Cscope 'cscope.lists' Multiple Buffer Overflow Vulnerabilities
BID:19686
CVE-2006-4262 |Info
Cscope 'cscope.lists' Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19686 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4262 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2006 12:00AM |
| Updated: | Jun 16 2009 02:09PM |
| Credit: | Will Drewry is credited with the discovery of this vulnerability. |
| Vulnerable: |
Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4.8.z Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4.8.z Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Cscope Cscope 15.5 Cscope Cscope 15.4 Cscope Cscope 15.3 Cscope Cscope 15.1 |
| Not Vulnerable: | |
Discussion
Cscope 'cscope.lists' Multiple Buffer Overflow Vulnerabilities
Cscope is prone to multiple buffer-overflow vulnerabilities because it fails to properly validate the size of attacker-supplied data before copying it into a finite-sized buffer.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running the application. Failed exploit attempts will likely crash the application, denying service to legitimate users.
Cscope 15.x is vulnerable; previous versions may be affected as well.
Cscope is prone to multiple buffer-overflow vulnerabilities because it fails to properly validate the size of attacker-supplied data before copying it into a finite-sized buffer.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running the application. Failed exploit attempts will likely crash the application, denying service to legitimate users.
Cscope 15.x is vulnerable; previous versions may be affected as well.
Exploit / POC
Cscope 'cscope.lists' Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cscope 'cscope.lists' Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor has released patches. Please see the references for details.
Solution:
The vendor has released patches. Please see the references for details.
References
Cscope 'cscope.lists' Multiple Buffer Overflow Vulnerabilities
References:
References: