innfeed Command-Line Buffer Overflow Vulnerability
BID:2620
Info
innfeed Command-Line Buffer Overflow Vulnerability
| Bugtraq ID: | 2620 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 18 2001 12:00AM |
| Updated: | Apr 18 2001 12:00AM |
| Credit: | This vulnerability was made public in an advisory released 18 April, 2001 by Enrique A. Sanchez Montellano <@defcom.com> |
| Vulnerable: |
ISC INN 2.2.3 ISC INN 2.2.2 ISC INN 2.2.1 ISC INN 2.2 ISC INN 2.1 ISC INN 2.0 |
| Not Vulnerable: |
ISC INN 2.3.1 ISC INN 2.3 |
Discussion
innfeed Command-Line Buffer Overflow Vulnerability
The innfeed utility, part of ISC InterNetNews, has an exploitable buffer overflow in its command-line parser. Specifically, innfeed will overflow if an overly long -c option is passed to it.
A local attacker in the news group could use this overflow to execute arbitary code with an effective userid of news, which could constitute an elevation in privileges, and the ability to alter news-owned binaries that could be run by root.
Exploits are available against x86 Linux builds of innfeed.
The innfeed utility, part of ISC InterNetNews, has an exploitable buffer overflow in its command-line parser. Specifically, innfeed will overflow if an overly long -c option is passed to it.
A local attacker in the news group could use this overflow to execute arbitary code with an effective userid of news, which could constitute an elevation in privileges, and the ability to alter news-owned binaries that could be run by root.
Exploits are available against x86 Linux builds of innfeed.
Exploit / POC
innfeed Command-Line Buffer Overflow Vulnerability
An exploit and a small script to brute-force addresses are available against x86 Linux builds of innfeed.
An exploit and a small script to brute-force addresses are available against x86 Linux builds of innfeed.
Solution / Fix
innfeed Command-Line Buffer Overflow Vulnerability
Solution:
ISC recommends that users upgrade INN to 2.3.0, which features a rewritten startinnfeed utility.
INN 2.3.1 is available:
ISC INN 2.0
ISC INN 2.1
ISC INN 2.2
ISC INN 2.2.1
ISC INN 2.2.2
ISC INN 2.2.3
Solution:
ISC recommends that users upgrade INN to 2.3.0, which features a rewritten startinnfeed utility.
INN 2.3.1 is available:
ISC INN 2.0
-
ISC INN 2.3.1
ftp://ftp.isc.org/isc/inn/inn-2.3.1.tar.gz
ISC INN 2.1
-
ISC INN 2.3.1
ftp://ftp.isc.org/isc/inn/inn-2.3.1.tar.gz
ISC INN 2.2
-
ISC INN 2.3.1
ftp://ftp.isc.org/isc/inn/inn-2.3.1.tar.gz
ISC INN 2.2.1
-
ISC INN 2.3.1
ftp://ftp.isc.org/isc/inn/inn-2.3.1.tar.gz
ISC INN 2.2.2
-
ISC INN 2.3.1
ftp://ftp.isc.org/isc/inn/inn-2.3.1.tar.gz
ISC INN 2.2.3
-
ISC INN 2.3.1
ftp://ftp.isc.org/isc/inn/inn-2.3.1.tar.gz