Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
BID:19707
CVE-2006-3124 |Info
Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 19707 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3124 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2006 12:00AM |
| Updated: | Oct 17 2006 11:19PM |
| Credit: | Ulf Harnhammar discovered this issue. |
| Vulnerable: |
Streamripper Streamripper 1.61.25 Streamripper Streamripper 1.61.24 Streamripper Streamripper 1.61.17 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Streamripper Streamripper 1.61.26 |
Discussion
Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
Streamripper is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.
An attacker may cause malicious code to execute by forcing the application to parse malformed HTTP headers, with the privileges of the user running the application.
Streamripper is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.
An attacker may cause malicious code to execute by forcing the application to parse malformed HTTP headers, with the privileges of the user running the application.
Exploit / POC
Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
Solution:
The vendor has released version 1.61.26 to address this issue.
Please see the referenced advisories for more information.
Streamripper Streamripper 1.61.17
Streamripper Streamripper 1.61.24
Streamripper Streamripper 1.61.25
Solution:
The vendor has released version 1.61.26 to address this issue.
Please see the referenced advisories for more information.
Streamripper Streamripper 1.61.17
-
Debian streamripper_1.61.7-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_alpha.deb -
Debian streamripper_1.61.7-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_amd64.deb -
Debian streamripper_1.61.7-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_arm.deb -
Debian streamripper_1.61.7-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_hppa.deb -
Debian streamripper_1.61.7-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_i386.deb -
Debian streamripper_1.61.7-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_ia64.deb -
Debian streamripper_1.61.7-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_m68k.deb -
Debian streamripper_1.61.7-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_mips.deb -
Debian streamripper_1.61.7-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_mipsel.deb -
Debian streamripper_1.61.7-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_powerpc.deb -
Debian streamripper_1.61.7-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_s390.deb -
Debian streamripper_1.61.7-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.7-1sarge1_sparc.deb
Streamripper Streamripper 1.61.24
-
Streamripper Streamripper 1.61.26
http://sourceforge.net/project/showfiles.php?group_id=6172
Streamripper Streamripper 1.61.25
-
Streamripper Streamripper 1.61.26
http://sourceforge.net/project/showfiles.php?group_id=6172
References
Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
References:
References:
- New for 1.61.26 (Streamripper)
- Streamripper Home Page (Streamripper)