PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
BID:26899
Info
PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26899 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6454 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | May 21 2008 01:44AM |
| Credit: | Luigi Auriemma is credited with the discovery of these issues. |
| Vulnerable: |
peercast.org PeerCast 0.1212 peercast.org PeerCast 0.1211 peercast.org PeerCast SVN 344 peercast.org PeerCast 0.1217 peercast.org PeerCast 0.1215 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
peercast.org PeerCast SVN 347 peercast.org PeerCast 0.1218 |
Discussion
PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
PeerCast is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized buffer.
Successfully exploiting these issues will allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect PeerCast 0.12.17, SVN 334 and prior versions.
PeerCast is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized buffer.
Successfully exploiting these issues will allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect PeerCast 0.12.17, SVN 334 and prior versions.
Exploit / POC
PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
peercast.org PeerCast 0.1217
peercast.org PeerCast 0.1215
peercast.org PeerCast 0.1211
peercast.org PeerCast 0.1212
Solution:
The vendor released an update to address these issues. Please see the references for more information.
peercast.org PeerCast 0.1217
-
peercast.org peercast-win32.exe
http://www.peercast.org/download.php
peercast.org PeerCast 0.1215
-
peercast.org peercast-win32.exe
http://www.peercast.org/download.php
peercast.org PeerCast 0.1211
-
peercast.org peercast-win32.exe
http://www.peercast.org/download.php
peercast.org PeerCast 0.1212
-
peercast.org peercast-win32.exe
http://www.peercast.org/download.php
References
PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
References:
References:
- PeerCast Homepage (peercast.org)
- Heap overflow in PeerCast 0.1217 (Luigi Auriemma
)