Berkeley Yacc (byacc) 'skeleton.c' Local Denial of Service Vulnerability
BID:30233
Info
Berkeley Yacc (byacc) 'skeleton.c' Local Denial of Service Vulnerability
| Bugtraq ID: | 30233 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 15 2008 12:00AM |
| Updated: | Jul 21 2008 10:58PM |
| Credit: | Otto Moerbeek |
| Vulnerable: |
Robert Corbett Berkeley Yacc (byacc) 20070509 Pardus Linux 2008 0 Pardus Linux 2007 0 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 2.0 OpenBSD OpenBSD 4.3 OpenBSD OpenBSD 4.2 OpenBSD OpenBSD 4.1 OpenBSD OpenBSD 4.0 OpenBSD OpenBSD 3.9 OpenBSD OpenBSD 3.8 OpenBSD OpenBSD 3.7 OpenBSD OpenBSD 3.6 OpenBSD OpenBSD 3.5 OpenBSD OpenBSD 3.4 OpenBSD OpenBSD 3.3 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 OpenBSD OpenBSD -current |
| Not Vulnerable: | |
Discussion
Berkeley Yacc (byacc) 'skeleton.c' Local Denial of Service Vulnerability
Berkeley Yacc (byacc) is prone to a local denial-of-service vulnerability because out-of-bounds stack memory may be accessed.
Attackers can exploit this issue to deny service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
This issue affects all versions of byacc; it was discovered in OpenBSD 4.3.
Berkeley Yacc (byacc) is prone to a local denial-of-service vulnerability because out-of-bounds stack memory may be accessed.
Attackers can exploit this issue to deny service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
This issue affects all versions of byacc; it was discovered in OpenBSD 4.3.
Exploit / POC
Berkeley Yacc (byacc) 'skeleton.c' Local Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Berkeley Yacc (byacc) 'skeleton.c' Local Denial of Service Vulnerability
Solution:
This issue was addressed in OpenBSD's CVS repository. Please see the references for more information.
Solution:
This issue was addressed in OpenBSD's CVS repository. Please see the references for more information.
References
Berkeley Yacc (byacc) 'skeleton.c' Local Denial of Service Vulnerability
References:
References:
- Berkeley Yacc (byacc) Homepage (Robert Corbett)
- openbsd-cvs (Otto Moerbeek)
- RCS file: /usr/OpenBSD/cvs/src/usr.bin/yacc/skeleton.c,v (OpenBSD)