SILC Client and Server Key Negotiation Protocol Remote Buffer Overflow Vulnerability
BID:28373
Info
SILC Client and Server Key Negotiation Protocol Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 28373 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1552 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2008 12:00AM |
| Updated: | Apr 13 2015 09:32PM |
| Credit: | Los Plomeros vs. Blue Demon, Ariel Waissbein, Pedro Varangot, Marti Mizrahi, Oren Isacson, Carlos Garcia and Ivan Arce |
| Vulnerable: |
SILC Server 1.1.1 SILC Server 1.0.2 SILC Client 1.1.3 SILC Client 1.1.2 SILC Client 1.1.1 S.u.S.E. openSUSE 10.3 Redhat Fedora 7 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Gentoo Linux |
| Not Vulnerable: |
SILC Server 1.1.2 SILC Client 1.1.4 |
Discussion
SILC Client and Server Key Negotiation Protocol Remote Buffer Overflow Vulnerability
SILC Client and Server are prone to a buffer-overflow vulnerability because they fail to perform adequate boundary checks on user-supplied input.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will cause denial-of-service conditions.
This issue affects versions prior to SILC Client 1.1.4 and SILC Server 1.1.2.
SILC Client and Server are prone to a buffer-overflow vulnerability because they fail to perform adequate boundary checks on user-supplied input.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will cause denial-of-service conditions.
This issue affects versions prior to SILC Client 1.1.4 and SILC Server 1.1.2.
Exploit / POC
SILC Client and Server Key Negotiation Protocol Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SILC Client and Server Key Negotiation Protocol Remote Buffer Overflow Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
SILC Server 1.0.2
SILC Server 1.1.1
SILC Client 1.1.1
SILC Client 1.1.2
SILC Client 1.1.3
Solution:
Vendor fixes are available. Please see the references for more information.
SILC Server 1.0.2
-
SILC silc-server-1.1.2.tar.gz
http://silcnet.org/download/server/sources/silc-server-1.1.2.tar.gz
SILC Server 1.1.1
-
SILC silc-server-1.1.2.tar.gz
http://silcnet.org/download/server/sources/silc-server-1.1.2.tar.gz
SILC Client 1.1.1
-
SILC silc-client-1.1.4.tar.gz
http://silcnet.org/download/client/sources/silc-client-1.1.4.tar.gz
SILC Client 1.1.2
-
SILC silc-client-1.1.4.tar.gz
http://silcnet.org/download/client/sources/silc-client-1.1.4.tar.gz
SILC Client 1.1.3
-
SILC silc-client-1.1.4.tar.gz
http://silcnet.org/download/client/sources/silc-client-1.1.4.tar.gz
References
SILC Client and Server Key Negotiation Protocol Remote Buffer Overflow Vulnerability
References:
References:
- SILC Client 1.1.4 Release Notes (SILC)
- SILC Server 1.1.2 Release Notes (SILC)
- SILC Webpage (SILC)
- CORE-2007-1212: SILC pkcs_decode buffer overflow (Core Security Technologies Advisories
)