CDF (Common Data Format) Library 'src/lib/cdfread64.c' Stack Based Buffer Overflow Vulnerability
BID:29045
Info
CDF (Common Data Format) Library 'src/lib/cdfread64.c' Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 29045 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2080 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2008 12:00AM |
| Updated: | May 13 2008 10:45PM |
| Credit: | Alfredo Ortega, from CORE IMPACT's Exploit Writing Team (EWT), Core Security Technologies |
| Vulnerable: |
NASA Goddard Space Flight Center CDF 3.2 Gentoo Linux |
| Not Vulnerable: |
NASA Goddard Space Flight Center CDF 3.2.1 |
Discussion
CDF (Common Data Format) Library 'src/lib/cdfread64.c' Stack Based Buffer Overflow Vulnerability
The CDF (Common Data Format) library is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data when processing CDF files.
Attackers can exploit this issue by enticing unsuspecting users to open malicious files. Successful exploits will allow code to run with the privileges of the user. Failed attacks will cause denial-of-service conditions.
CDF 3.2 and prior versions are vulnerable.
The CDF (Common Data Format) library is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data when processing CDF files.
Attackers can exploit this issue by enticing unsuspecting users to open malicious files. Successful exploits will allow code to run with the privileges of the user. Failed attacks will cause denial-of-service conditions.
CDF 3.2 and prior versions are vulnerable.
Exploit / POC
CDF (Common Data Format) Library 'src/lib/cdfread64.c' Stack Based Buffer Overflow Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
CDF (Common Data Format) Library 'src/lib/cdfread64.c' Stack Based Buffer Overflow Vulnerability
Solution:
The vendor released CDF 3.2.1 to address this issue. Please see the references for more information.
Solution:
The vendor released CDF 3.2.1 to address this issue. Please see the references for more information.
References
CDF (Common Data Format) Library 'src/lib/cdfread64.c' Stack Based Buffer Overflow Vulnerability
References:
References:
- Common Data Format (CDF) Version 3.2 and earlier Buffer Overflow Vulnerability (NASA Goddard Space Flight Center)
- CORE-2008-0326 NASA's Common Data Format buffer overflow (Core Security Technologies)
- Download the latest version of CDF Software Distribution (V3.2.1) (NASA Goddard Space Flight Center)
- Vendor Homepage (NASA Goddard Space Flight Center)