MUSCLE 'Message::AddToString()' Buffer Overflow Vulnerability
BID:31822
Info
MUSCLE 'Message::AddToString()' Buffer Overflow Vulnerability
| Bugtraq ID: | 31822 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4631 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Meyer Sound Laboratories Inc |
| Vulnerable: |
Meyer Sound Laboratories Inc Multi User Server Client Linkage Environment 4.30 |
| Not Vulnerable: |
Meyer Sound Laboratories Inc Multi User Server Client Linkage Environment 4.40 |
Discussion
MUSCLE 'Message::AddToString()' Buffer Overflow Vulnerability
MUSCLE is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of an application using the vulnerable library. This can compromise the affected application and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
This issue affects MUSCLE 4.30; previous versions may also be vulnerable.
MUSCLE is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of an application using the vulnerable library. This can compromise the affected application and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
This issue affects MUSCLE 4.30; previous versions may also be vulnerable.
Exploit / POC
MUSCLE 'Message::AddToString()' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MUSCLE 'Message::AddToString()' Buffer Overflow Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Solution:
The vendor released updates to address this issue. Please see the references for more information.
References
MUSCLE 'Message::AddToString()' Buffer Overflow Vulnerability
References:
References:
- Multi User Server Client Linkage Environment Homepage (Meyer Sound Laboratories Inc)
- MUSCLE change history (Meyer Sound Laboratories Inc)