Xsupplicant Stack Buffer Overflow Vulnerability
BID:20775
Info
Xsupplicant Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 20775 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5601 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2006 12:00AM |
| Updated: | Jan 25 2007 04:21PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SP3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 10.1 open1x xsupplicant 1.2.6 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 |
| Not Vulnerable: |
open1x xsupplicant 1.2.8 |
Discussion
Xsupplicant Stack Buffer Overflow Vulnerability
Xsupplicant is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application. Failed attempts will likely crash the application, resulting in denial-of-service conditions.
Xsupplicant versions prior to 1.2.8 are reported vulnerable.
Xsupplicant is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application. Failed attempts will likely crash the application, resulting in denial-of-service conditions.
Xsupplicant versions prior to 1.2.8 are reported vulnerable.
Exploit / POC
Xsupplicant Stack Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Xsupplicant Stack Buffer Overflow Vulnerability
Solution:
The vendor has released version 1.2.8 to address this issue. Please see the references section for more information.
mailto:[email protected]
open1x xsupplicant 1.2.6
Solution:
The vendor has released version 1.2.8 to address this issue. Please see the references section for more information.
mailto:[email protected]
open1x xsupplicant 1.2.6
-
open1x xsupplicant-1.2.8.tar.gz
http://prdownloads.sourceforge.net/open1x/xsupplicant-1.2.8.tar.gz
References
Xsupplicant Stack Buffer Overflow Vulnerability
References:
References:
- Release Name: Xsupplicant 1.2.8 - possible remote root exploit. (Xsupplicant)
- Xsupplicant Web Site (Xsupplicant)