rdesktop Multiple Remote Memory Corruption Vulnerabilities
BID:29097
Info
rdesktop Multiple Remote Memory Corruption Vulnerabilities
| Bugtraq ID: | 29097 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1801 CVE-2008-1802 CVE-2008-1803 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2008 12:00AM |
| Updated: | Apr 13 2015 10:24PM |
| Credit: | The discoverer of these vulnerabilities wishes to remain anonymous. These issues were disclosed in the referenced iDefense advisories. |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_85 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server rdesktop rdesktop 1.5 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: | |
Discussion
rdesktop Multiple Remote Memory Corruption Vulnerabilities
The 'rdesktop' program is prone to multiple remote memory-corruption vulnerabilities because it fails to properly validate incoming packets.
A remote attacker can exploit these issues to execute arbitrary code in the context of the currently logged-in user.
These issues affect rdesktop 1.5.0; other versions may also be vulnerable.
The 'rdesktop' program is prone to multiple remote memory-corruption vulnerabilities because it fails to properly validate incoming packets.
A remote attacker can exploit these issues to execute arbitrary code in the context of the currently logged-in user.
These issues affect rdesktop 1.5.0; other versions may also be vulnerable.
Exploit / POC
rdesktop Multiple Remote Memory Corruption Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof-of-concept code is available for the integer-underflow issue and buffer-overflow issue:
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof-of-concept code is available for the integer-underflow issue and buffer-overflow issue:
Solution / Fix
rdesktop Multiple Remote Memory Corruption Vulnerabilities
Solution:
The vendor has addressed these issues in the latest CVS repository. Contact the vendor for details on obtaining the appropriate updates.
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 7.10 sparc
Ubuntu Ubuntu Linux 7.04 i386
Ubuntu Ubuntu Linux 7.04 amd64
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 7.10 lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 7.10 i386
Ubuntu Ubuntu Linux 6.06 LTS amd64
Ubuntu Ubuntu Linux 7.10 amd64
Ubuntu Ubuntu Linux 7.04 powerpc
Ubuntu Ubuntu Linux 7.04 sparc
Solution:
The vendor has addressed these issues in the latest CVS repository. Contact the vendor for details on obtaining the appropriate updates.
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu rdesktop_1.5.0-2ubuntu0.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 2ubuntu0.1_powerpc.deb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06.1_sparc.deb -
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06_sparc.deb
Ubuntu Ubuntu Linux 7.10 sparc
-
Ubuntu rdesktop_1.5.0-2ubuntu0.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 2ubuntu0.1_sparc.deb
Ubuntu Ubuntu Linux 7.04 i386
-
Ubuntu rdesktop_1.5.0-1ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 1ubuntu1.1_i386.deb
Ubuntu Ubuntu Linux 7.04 amd64
-
Ubuntu rdesktop_1.5.0-1ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 1ubuntu1.1_amd64.deb
Ubuntu Ubuntu Linux 6.06 LTS powerpc
-
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06.1_powerpc.deb -
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06_powerpc.deb
Ubuntu Ubuntu Linux 7.10 lpia
-
Ubuntu rdesktop_1.5.0-2ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/r/rdesktop/rdesktop_1.5.0-2ubuntu0.1 _lpia.deb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06.1_i386.deb -
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06_i386.deb
Ubuntu Ubuntu Linux 7.10 i386
-
Ubuntu rdesktop_1.5.0-2ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 2ubuntu0.1_i386.deb
Ubuntu Ubuntu Linux 6.06 LTS amd64
-
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06.1_amd64.deb -
Ubuntu rdesktop_1.4.1-1.1ubuntu0.6.06_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1- 1.1ubuntu0.6.06_amd64.deb
Ubuntu Ubuntu Linux 7.10 amd64
-
Ubuntu rdesktop_1.5.0-2ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 2ubuntu0.1_amd64.deb
Ubuntu Ubuntu Linux 7.04 powerpc
-
Ubuntu rdesktop_1.5.0-1ubuntu1.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 1ubuntu1.1_powerpc.deb
Ubuntu Ubuntu Linux 7.04 sparc
-
Ubuntu rdesktop_1.5.0-1ubuntu1.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0- 1ubuntu1.1_sparc.deb
References
rdesktop Multiple Remote Memory Corruption Vulnerabilities
References:
References:
- Annotation of /rdesktop/iso.c (rdesktop)
- Multiple Vendor rdesktop process_redirect_pdu() BSS Overflow Vulnerability (iDefense)
- rdesktop Sourceforge page (rdesktop)
- iDefense Security Advisory 05.07.08: Multiple Vendor rdesktop channel_process() (iDefense Labs
) - iDefense Security Advisory 05.07.08: Multiple Vendor rdesktop iso_recv_msg() Int (iDefense Labs
) - iDefense Security Advisory 05.07.08: Multiple Vendor rdesktop process_redirect_p (iDefense Labs
) - ASA-2008-331 rdesktop security and bug fix update (RHSA-2008-0725) (Avaya )
- Multiple Vendor rdesktop channel_process() Integer Signedness Vulnerability (iDefense)
- Multiple Vendor rdesktop iso_recv_msg() Integer Underflow Vulnerability (iDefense)
- RHSA-2008:0575-5 rdesktop security update (Red Hat)
- RHSA-2008:0576-3 rdesktop security update (Red Hat)
- RHSA-2008:0725-7 rdesktop security and bug fix update (Red Hat)
- Sun Security Advisory 240708 (Sun Microsystems)