Red Hat Cluster Suite CMan Local Buffer Overflow Vulnerability
BID:24595
Info
Red Hat Cluster Suite CMan Local Buffer Overflow Vulnerability
| Bugtraq ID: | 24595 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3374 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 22 2007 12:00AM |
| Updated: | Jun 29 2007 03:18PM |
| Credit: | Fabio Massimo Di Nitto discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Redhat Cluster Suite 0 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux 5 Server Redhat Cluster Suite 0 |
| Not Vulnerable: | |
Discussion
Red Hat Cluster Suite CMan Local Buffer Overflow Vulnerability
Red Hat Cluster Suite is prone to an unspecified remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with 'cluster manager' privileges. Failed exploit attempts will result in a denial of service.
NOTE: This issue was originally reported in the Ubuntu distribution of the software, but other distributions may also be affected.
Red Hat Cluster Suite is prone to an unspecified remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with 'cluster manager' privileges. Failed exploit attempts will result in a denial of service.
NOTE: This issue was originally reported in the Ubuntu distribution of the software, but other distributions may also be affected.
Exploit / POC
Red Hat Cluster Suite CMan Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Red Hat Cluster Suite CMan Local Buffer Overflow Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Redhat Cluster Suite 0
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Redhat Cluster Suite 0
References
Red Hat Cluster Suite CMan Local Buffer Overflow Vulnerability
References:
References:
- [Cluster-devel] cluster/cman/daemon daemon.c (Red Hat)
- [Cluster-devel] cluster/cman/daemon daemon.c (Red Hat)
- Bug #121780 in redhat-cluster-suite (Ubuntu) (Ubuntu)
- RHSA-2007:0559-2 - cman security update (RedHat)
- Ubuntu Homepage (Ubuntu)