White_Dune Multiple Local Code Execution Vulnerabilities
BID:27102
Info
White_Dune Multiple Local Code Execution Vulnerabilities
| Bugtraq ID: | 27102 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0101 CVE-2008-0100 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 02 2008 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Luigi Auriemma is credited with discovering these vulnerabilities. |
| Vulnerable: |
White_Dune White_Dune 0.29beta791 |
| Not Vulnerable: |
White_Dune White_Dune 0.29beta795 |
Discussion
White_Dune Multiple Local Code Execution Vulnerabilities
White_Dune is affected by a format-string vulnerability and a buffer-overflow vulnerability.
Exploiting these issues can allow local attackers to execute arbitrary code in the context of the application.
Versions prior to White_Dune 0.29beta795 are affected.
White_Dune is affected by a format-string vulnerability and a buffer-overflow vulnerability.
Exploiting these issues can allow local attackers to execute arbitrary code in the context of the application.
Versions prior to White_Dune 0.29beta795 are affected.
Exploit / POC
White_Dune Multiple Local Code Execution Vulnerabilities
The following proof-of-concept examples are available:
The following proof-of-concept examples are available:
Solution / Fix
White_Dune Multiple Local Code Execution Vulnerabilities
Solution:
The vendor released White_Dune 0.29beta795 to address these issues.
White_Dune White_Dune 0.29beta791
Solution:
The vendor released White_Dune 0.29beta795 to address these issues.
White_Dune White_Dune 0.29beta791
-
White_Dune white_dune-0.29beta795.tar.gz
http://129.69.35.12/dune/white_dune-0.29beta795.tar.gz
References
White_Dune Multiple Local Code Execution Vulnerabilities
References:
References:
- White_Dune Homepage (White_Dune)
- Buffer-overflow and format string in White_Dune 0.29beta791 (Luigi Auriemma
)