NuFW SAMP_SEND Heap Based Buffer Overflow Vulnerability
BID:26251
Info
NuFW SAMP_SEND Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 26251 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5723 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
NuFW NuFW 2.2.6 |
| Not Vulnerable: |
NuFW NuFW 2.2.7 |
Discussion
NuFW SAMP_SEND Heap Based Buffer Overflow Vulnerability
NuFW is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial of service.
This issue affects NuFW 2.2.6; other versions may also be vulnerable.
NuFW is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial of service.
This issue affects NuFW 2.2.6; other versions may also be vulnerable.
Exploit / POC
NuFW SAMP_SEND Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NuFW SAMP_SEND Heap Based Buffer Overflow Vulnerability
Solution:
The vendor released NuFW 2.2.7 to address this issue. Please see the references for more information.
NuFW NuFW 2.2.6
Solution:
The vendor released NuFW 2.2.7 to address this issue. Please see the references for more information.
NuFW NuFW 2.2.6
-
NuFW NuFW 2.2.7
http://www.nufw.org/download/nufw/nufw-2.2.7.tar.bz2
References
NuFW SAMP_SEND Heap Based Buffer Overflow Vulnerability
References:
References:
- NuFW 2.2.7 release (NuFW)
- NuFW Home Page (NuFW)