cfingerd Utilities Buffer Overflow Vulnerability
BID:2914
Info
cfingerd Utilities Buffer Overflow Vulnerability
| Bugtraq ID: | 2914 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0735 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 21 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was announced to Bugtraq by Steven Van Acker <[email protected]> on June 21, 2001. |
| Vulnerable: |
Martin Schulze Cfingerd 1.4.3 Martin Schulze Cfingerd 1.4.2 Martin Schulze Cfingerd 1.4.1 |
| Not Vulnerable: | |
Exploit / POC
cfingerd Utilities Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
cfingerd Utilities Buffer Overflow Vulnerability
Solution:
Steven Van Acker <[email protected]> supplied this fix:
on line 181:
while((newpos < 80) && (line[pos] != ' ') && (!done)) {
^^^^^^^^^^^^^^^^^
on line 301:
printf("%s",displine);
^^^^^
Then recompile.
Debian has released upgraded packages.
Martin Schulze Cfingerd 1.4.1
Solution:
Steven Van Acker <[email protected]> supplied this fix:
on line 181:
while((newpos < 80) && (line[pos] != ' ') && (!done)) {
^^^^^^^^^^^^^^^^^
on line 301:
printf("%s",displine);
^^^^^
Then recompile.
Debian has released upgraded packages.
Martin Schulze Cfingerd 1.4.1
-
Debian 2.2 alpha cfingerd_1.4.1-1.2_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/cfin gerd_1.4.1-1.2_alpha.deb -
Debian 2.2 arm cfingerd_1.4.1-1.2_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/cfinge rd_1.4.1-1.2_arm.deb -
Debian 2.2 i386 cfingerd_1.4.1-1.2_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/cfing erd_1.4.1-1.2_i386.deb -
Debian 2.2 m68k cfingerd_1.4.1-1.2_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/cfing erd_1.4.1-1.2_m68k.deb -
Debian 2.2 ppc cfingerd_1.4.1-1.2_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/cf ingerd_1.4.1-1.2_powerpc.deb -
Debian 2.2 sparc cfingerd_1.4.1-1.2_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/cfin gerd_1.4.1-1.2_sparc.deb
References
cfingerd Utilities Buffer Overflow Vulnerability
References:
References: