cfingerd Format String Vulnerability
BID:2576
Info
cfingerd Format String Vulnerability
| Bugtraq ID: | 2576 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0609 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was made public in an advisory posted to BugTraq by Megyer Laszlo <mailto:[email protected]> on 11 April, 2001. |
| Vulnerable: |
Infodrom cfingerd 1.4 .3 Infodrom cfingerd 1.4 .2 Infodrom cfingerd 1.4 .1 Infodrom cfingerd 1.4 .0 |
| Not Vulnerable: | |
Discussion
cfingerd Format String Vulnerability
A format string bug in the logging facility of the cfingerd "Configurable Finger Daemon" allows remote users to attain root privileges and execute arbitrary code.
cfingerd queries and logs the remote username of users of the service. If an attacker sets up a remote machine that returns specific format strings instead of a valid username, and connects to cfingerd from that machine, he can exploit the format string bugs. Because cfingerd runs as root, this means the attacker gains full control of the cfingerd host.
An exploit is available against x86 versions of cfingerd.
A format string bug in the logging facility of the cfingerd "Configurable Finger Daemon" allows remote users to attain root privileges and execute arbitrary code.
cfingerd queries and logs the remote username of users of the service. If an attacker sets up a remote machine that returns specific format strings instead of a valid username, and connects to cfingerd from that machine, he can exploit the format string bugs. Because cfingerd runs as root, this means the attacker gains full control of the cfingerd host.
An exploit is available against x86 versions of cfingerd.
Exploit / POC
cfingerd Format String Vulnerability
An exploit written in perl is available against x86 versions of cfingerd. Because the exploit listens on the identd port, it must be run as root.
An exploit written in perl is available against x86 versions of cfingerd. Because the exploit listens on the identd port, it must be run as root.
Solution / Fix
cfingerd Format String Vulnerability
Solution:
Patches are available against cfingerd 1.4.3 that address the syslog format-string bugs and a single NULL-byte buffer overflow issue:
Infodrom cfingerd 1.4 .1
Infodrom cfingerd 1.4 .3
Solution:
Patches are available against cfingerd 1.4.3 that address the syslog format-string bugs and a single NULL-byte buffer overflow issue:
Infodrom cfingerd 1.4 .1
-
Debian cfingerd_1.4.1-1.1 Source diff
Source patch to cfingerd 1.4.1
http://security.debian.org/dists/stable/updates/main/source/cfingerd_1 .4.1-1.1.diff.gz -
Debian cfingerd_1.4.1-1.1 alpha
Patched release of cfingerd 1.4.1
http://security.debian.org/dists/stable/updates/main/binary-alpha/cfin gerd_1.4.1-1.1_alpha.deb -
Debian cfingerd_1.4.1-1.1 arm
Patched release of cfingerd 1.4.1
http://security.debian.org/dists/stable/updates/main/binary-arm/cfinge rd_1.4.1-1.1_arm.deb -
Debian cfingerd_1.4.1-1.1 i386
Patched release of cfingerd 1.4.1
http://security.debian.org/dists/stable/updates/main/binary-i386/cfing erd_1.4.1-1.1_i386.deb -
Debian cfingerd_1.4.1-1.1 m68k
Patched release of cfingerd 1.4.1
http://security.debian.org/dists/stable/updates/main/binary-m68k/cfing erd_1.4.1-1.1_m68k.deb -
Debian cfingerd_1.4.1-1.1 powerpc
Patched release of cfingerd 1.4.1
http://security.debian.org/dists/stable/updates/main/binary-powerpc/cf ingerd_1.4.1-1.1_powerpc.deb -
Debian cfingerd_1.4.1-1.1 sparc
Patched release of cfingerd 1.4.1
http://security.debian.org/dists/stable/updates/main/binary-sparc/cfin gerd_1.4.1-1.1_sparc.deb -
Progeny cfingerd_1.4.1-1.1
http://archive.progeny.com/progeny/updates/newton/cfingerd_1.4.1-1.1_i 386.deb
Infodrom cfingerd 1.4 .3
-
Megyer Laszlo
cfingerd patch
http://www.securityfocus.com/data/vulnerabilities/patches/cfingerd-1.4 .3.diff