Iomega JaZip Buffer Overflow Vulnerability
BID:2209
Info
Iomega JaZip Buffer Overflow Vulnerability
| Bugtraq ID: | 2209 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 14 2001 12:00AM |
| Updated: | Jan 14 2001 12:00AM |
| Credit: | Reported to bugtraq by teleh0r <[email protected]> on Sun, 14 Jan 2001 |
| Vulnerable: |
Iomega JaZip 0.32 -2 |
| Not Vulnerable: | |
Discussion
Iomega JaZip Buffer Overflow Vulnerability
Iomega jaZip, a Unix utility for managing Zip and Jaz removable media, fails to properly validate user-supplied input to the DISPLAY environment variable.
If properly exploited, this can yield root privilege to the attacker.
Iomega jaZip, a Unix utility for managing Zip and Jaz removable media, fails to properly validate user-supplied input to the DISPLAY environment variable.
If properly exploited, this can yield root privilege to the attacker.
Solution / Fix
Iomega JaZip Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Iomega JaZip 0.32 -2
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Iomega JaZip 0.32 -2
-
Debian jazip_0.33-1_alpha.deb
Debian 2.2 (potato)
http://security.debian.org/dists/stable/updates/main/binary-alpha/jazi p_0.33-1_alpha.deb -
Debian jazip_0.33-1_arm.deb
Debian 2.2 (potato)
http://security.debian.org/dists/stable/updates/main/binary-alpha/jazi p_0.33-1_arm.deb -
Debian jazip_0.33-1_i386.deb
Debian 2.2 (potato)
http://security.debian.org/dists/stable/updates/main/binary-alpha/jazi p_0.33-1_i386.deb -
Debian jazip_0.33-1_m68k.deb
Debian 2.2 (potato)
http://security.debian.org/dists/stable/updates/main/binary-m68k/jazip _0.33-1_m68k.deb -
Debian jazip_0.33-1_powerpc.deb
Debian 2.2 (potato)
http://security.debian.org/dists/stable/updates/main/binary-powerpc/ja zip_0.33-1_powerpc.deb -
Debian jazip_0.33-1_sparc.deb
Debian 2.2 (potato)
http://security.debian.org/dists/stable/updates/main/binary-sparc/jazi p_0.33-1_sparc.deb