TCPreen 'FD_SET()' Remote Buffer Overflow Vulnerability
BID:27018
Info
TCPreen 'FD_SET()' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27018 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6562 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2007 12:00AM |
| Updated: | Jan 04 2008 05:50PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
TCPreen TCPreen 1.4.3 TCPreen TCPreen 1.4.2 TCPreen TCPreen 1.4.1 TCPreen TCPreen 1.4 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
TCPreen TCPreen 1.4.4 |
Discussion
TCPreen 'FD_SET()' Remote Buffer Overflow Vulnerability
TCPreen is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Successful attacks may compromise affected computers. Failed exploit attempts will result in a denial of service.
Versions prior to TCPreen 1.4.4 are vulnerable.
TCPreen is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Successful attacks may compromise affected computers. Failed exploit attempts will result in a denial of service.
Versions prior to TCPreen 1.4.4 are vulnerable.
Exploit / POC
TCPreen 'FD_SET()' Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
TCPreen 'FD_SET()' Remote Buffer Overflow Vulnerability
Solution:
The vendor released TCPreen 1.4.4 to address this issue. Please see the references for more information.
TCPreen TCPreen 1.4
TCPreen TCPreen 1.4.1
TCPreen TCPreen 1.4.2
TCPreen TCPreen 1.4.3
Solution:
The vendor released TCPreen 1.4.4 to address this issue. Please see the references for more information.
TCPreen TCPreen 1.4
-
TCPreen TCPreen 1.4.4
http://www.remlab.net/tcpreen/#platform
TCPreen TCPreen 1.4.1
-
TCPreen TCPreen 1.4.4
http://www.remlab.net/tcpreen/#platform
TCPreen TCPreen 1.4.2
-
TCPreen TCPreen 1.4.4
http://www.remlab.net/tcpreen/#platform
TCPreen TCPreen 1.4.3
-
TCPreen TCPreen 1.4.4
http://www.remlab.net/tcpreen/#platform
References
TCPreen 'FD_SET()' Remote Buffer Overflow Vulnerability
References:
References:
- Product Page (TCPreen)
- RELEASE NOTES for TCPreen version 1.4.4 (stable release) (TCPreen)