qDecoder Remote Buffer Overflow Vulnerability
BID:2329
Info
qDecoder Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 2329 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0173 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 30 2001 12:00AM |
| Updated: | Jul 11 2009 04:46AM |
| Credit: | reported to bugtraq by "You, Jin-Ho" <[email protected]> on Tue, 30 Jan 2001. |
| Vulnerable: |
qDecoder qDecoder 5.0.3 qDecoder qDecoder 5.0.2 qDecoder qDecoder 5.0.1 qDecoder qDecoder 5.0 qDecoder qDecoder 4.3.1 qDecoder qDecoder 4.3 qDecoder qDecoder 4.0.1 qDecoder qDecoder 4.0 |
| Not Vulnerable: |
qDecoder qDecoder 6.0.3 |
Discussion
qDecoder Remote Buffer Overflow Vulnerability
Improperly validated user-supplied input to the Content-Type header can create an overflow condition.
As a result, excessive data copied onto the stack can overwrite critical parts of the stack frame such as the calling functions' return address, potentially allowing remote code execution with the privileges of the webserver.
Improperly validated user-supplied input to the Content-Type header can create an overflow condition.
As a result, excessive data copied onto the stack can overwrite critical parts of the stack frame such as the calling functions' return address, potentially allowing remote code execution with the privileges of the webserver.
Exploit / POC
qDecoder Remote Buffer Overflow Vulnerability
crazywww.pl exploit was provided by "You, Jin-Ho" <[email protected]>.
crazywww.pl exploit was provided by "You, Jin-Ho" <[email protected]>.
Solution / Fix
qDecoder Remote Buffer Overflow Vulnerability
Solution:
qdecoder.diff patch was provided by "You, Jin-Ho" <[email protected]>.
qDecoder qDecoder 4.0
qDecoder qDecoder 4.0.1
qDecoder qDecoder 4.3
qDecoder qDecoder 4.3.1
qDecoder qDecoder 5.0
qDecoder qDecoder 5.0.1
qDecoder qDecoder 5.0.2
qDecoder qDecoder 5.0.3
Solution:
qdecoder.diff patch was provided by "You, Jin-Ho" <[email protected]>.
qDecoder qDecoder 4.0
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
qDecoder qDecoder 4.0.1
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
qDecoder qDecoder 4.3
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
qDecoder qDecoder 4.3.1
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
qDecoder qDecoder 5.0
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
qDecoder qDecoder 5.0.1
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
qDecoder qDecoder 5.0.2
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
qDecoder qDecoder 5.0.3
-
You, Jin-Ho
qdecoder.diff
/sfweb/data/vulnerabilities/patches/qdecoder.diff
References
qDecoder Remote Buffer Overflow Vulnerability
References:
References: