NASM 'ppscan()' Off-By-One Buffer Overflow Vulnerability
BID:29656
Info
NASM 'ppscan()' Off-By-One Buffer Overflow Vulnerability
| Bugtraq ID: | 29656 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2719 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2008 12:00AM |
| Updated: | Sep 30 2008 10:38PM |
| Credit: | Philipp Thomas |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 NASM NASM 2.0.2 NASM NASM 2.0.1 NASM NASM 2.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 |
| Not Vulnerable: |
NASM NASM 2.0.3 |
Discussion
NASM 'ppscan()' Off-By-One Buffer Overflow Vulnerability
NASM is prone to an off-by-one buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
NASM 2.02 and prior versions are vulnerable.
NASM is prone to an off-by-one buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
NASM 2.02 and prior versions are vulnerable.
Exploit / POC
NASM 'ppscan()' Off-By-One Buffer Overflow Vulnerability
A proof of concept causing a crash is available. Symantec has not tested or verified this code.
A proof of concept causing a crash is available. Symantec has not tested or verified this code.
Solution / Fix
NASM 'ppscan()' Off-By-One Buffer Overflow Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 8.04 LTS lpia
Solution:
The vendor has released fixes. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu nasm_0.99.06-2ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nasm/nasm_0.99.06-2ubunt u0.1_i386.deb
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu nasm_0.99.06-2ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nasm/nasm_0.99.06-2ubunt u0.1_amd64.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu nasm_0.99.06-2ubuntu0.1_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nasm/nasm_0.99.06-2ubuntu0.1_power pc.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu nasm_0.99.06-2ubuntu0.1_sparc.deb
http://ports.ubuntu.com/pool/main/n/nasm/nasm_0.99.06-2ubuntu0.1_sparc .deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu nasm_0.99.06-2ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/n/nasm/nasm_0.99.06-2ubuntu0.1_lpia. deb
References
NASM 'ppscan()' Off-By-One Buffer Overflow Vulnerability
References:
References:
- nasm 2.02 triggers stack guard in glibc 2.7 (NASM)
- NASM Homepage (NASM)
- The Netwide Assembler (NASM)