Streamripper HTTP Header Parsing Buffer Overflow Vulnerabilities
BID:25278
Info
Streamripper HTTP Header Parsing Buffer Overflow Vulnerabilities
| Bugtraq ID: | 25278 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-4337 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2007 12:00AM |
| Updated: | Dec 08 2008 11:51PM |
| Credit: | The vendor reported these vulnerabilities. |
| Vulnerable: |
Streamripper Streamripper 1.62.1 Streamripper Streamripper 1.62 Streamripper Streamripper 1.61.26 Streamripper Streamripper 1.61.25 Streamripper Streamripper 1.61.24 Streamripper Streamripper 1.61.17 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Streamripper Streamripper 1.62.2 |
Discussion
Streamripper HTTP Header Parsing Buffer Overflow Vulnerabilities
Streamripper is prone to two remote buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into insufficiently sized buffers.
An attacker may exploit these issues to execute arbitrary code within the context of the affected application or crash the application, denying service to legitimate users.
Versions prior to Streamripper 1.62.2 are vulnerable.
Streamripper is prone to two remote buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into insufficiently sized buffers.
An attacker may exploit these issues to execute arbitrary code within the context of the affected application or crash the application, denying service to legitimate users.
Versions prior to Streamripper 1.62.2 are vulnerable.
Exploit / POC
Streamripper HTTP Header Parsing Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Streamripper HTTP Header Parsing Buffer Overflow Vulnerabilities
Solution:
The vendor has released Streamripper 1.62.2 to address these issues.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 4.0 mipsel
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Streamripper Streamripper 1.61.17
Streamripper Streamripper 1.61.24
Streamripper Streamripper 1.61.25
Streamripper Streamripper 1.61.26
Streamripper Streamripper 1.62
Streamripper Streamripper 1.62.1
Solution:
The vendor has released Streamripper 1.62.2 to address these issues.
Debian Linux 4.0 amd64
-
Debian streamripper_1.61.27-1+etch1_amd64.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_amd64.deb
Debian Linux 4.0 ia-32
-
Debian streamripper_1.61.27-1+etch1_i386.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_i386.deb
Debian Linux 4.0 arm
-
Debian streamripper_1.61.27-1+etch1_arm.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_arm.deb
Debian Linux 4.0 hppa
-
Debian streamripper_1.61.27-1+etch1_hppa.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_hppa.deb
Debian Linux 4.0 sparc
-
Debian streamripper_1.61.27-1+etch1_sparc.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_sparc.deb
Debian Linux 4.0 s/390
-
Debian streamripper_1.61.27-1+etch1_s390.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_s390.deb
Debian Linux 4.0 powerpc
-
Debian streamripper_1.61.27-1+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_powerpc.deb
Debian Linux 4.0 alpha
-
Debian streamripper_1.61.27-1+etch1_alpha.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_alpha.deb
Debian Linux 4.0 mipsel
-
Debian streamripper_1.61.27-1+etch1_mipsel.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_mipsel.deb
Debian Linux 4.0 ia-64
-
Debian streamripper_1.61.27-1+etch1_ia64.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_ia64.deb
Debian Linux 4.0 mips
-
Debian streamripper_1.61.27-1+etch1_mips.deb
http://security.debian.org/pool/updates/main/s/streamripper/streamripp er_1.61.27-1+etch1_mips.deb
Streamripper Streamripper 1.61.17
-
Streamripper Streamripper 1.62.2
http://sourceforge.net/project/showfiles.php?group_id=6172
Streamripper Streamripper 1.61.24
-
Streamripper Streamripper 1.62.2
http://sourceforge.net/project/showfiles.php?group_id=6172
Streamripper Streamripper 1.61.25
-
Streamripper Streamripper 1.62.2
http://sourceforge.net/project/showfiles.php?group_id=6172
Streamripper Streamripper 1.61.26
-
Streamripper Streamripper 1.62.2
http://sourceforge.net/project/showfiles.php?group_id=6172
Streamripper Streamripper 1.62
-
Streamripper Streamripper 1.62.2
http://sourceforge.net/project/showfiles.php?group_id=6172
Streamripper Streamripper 1.62.1
-
Streamripper Streamripper 1.62.2
http://sourceforge.net/project/showfiles.php?group_id=6172
References
Streamripper HTTP Header Parsing Buffer Overflow Vulnerabilities
References:
References:
- Release Name: 1.62.2 (Streamripper)
- Streamripper Home Page (Streamripper)
- Streamripper 1.62.1 - Buffer Overflows ([email protected])