John E. Davis MOST Buffer Overflow Vulnerability
BID:3347
Info
John E. Davis MOST Buffer Overflow Vulnerability
| Bugtraq ID: | 3347 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 18 2001 12:00AM |
| Updated: | Sep 18 2001 12:00AM |
| Credit: | This vulnerability was described in a Debian Security Advisory that was published on September 18th, 2001. |
| Vulnerable: |
John E. Davis MOST 4.41 John E. Davis MOST 4.9.1 John E. Davis MOST 4.9 .0 John E. Davis MOST 4.7 John E. Davis MOST 4.6 John E. Davis MOST 4.5 John E. Davis MOST 4.4 |
| Not Vulnerable: |
John E. Davis MOST 4.9.2 |
Discussion
John E. Davis MOST Buffer Overflow Vulnerability
MOST is an open source paging program that is written and maintained by John E. Davis.
An exploitable buffer overflow exists in MOST. This is due to improper bounds checking of certain variables. It is possible for a remote or a local attacker to create a file which, when viewed by MOST, will cause arbitrary code to executed on the host. This is accomplished by using a malicious file to overwrite stack variables(including the return address). Arbitrary code will be executed as the UID of of the user running MOST.
Successful exploitation could allow a remote attacker to gain local access to a host or allow a local attacker to gain elevated privileges.
MOST is an open source paging program that is written and maintained by John E. Davis.
An exploitable buffer overflow exists in MOST. This is due to improper bounds checking of certain variables. It is possible for a remote or a local attacker to create a file which, when viewed by MOST, will cause arbitrary code to executed on the host. This is accomplished by using a malicious file to overwrite stack variables(including the return address). Arbitrary code will be executed as the UID of of the user running MOST.
Successful exploitation could allow a remote attacker to gain local access to a host or allow a local attacker to gain elevated privileges.
Exploit / POC
John E. Davis MOST Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
John E. Davis MOST Buffer Overflow Vulnerability
Solution:
Updates are available.
John E. Davis MOST 4.9 .0
Solution:
Updates are available.
John E. Davis MOST 4.9 .0
-
Debian 2.2 alpha most_4.9.0-2.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/most _4.9.0-2.1_alpha.deb -
Debian 2.2 arm most_4.9.0-2.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/most_4 .9.0-2.1_arm.deb -
Debian 2.2 i386 most_4.9.0-2.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/most_ 4.9.0-2.1_i386.deb -
Debian 2.2 m68k most_4.9.0-2.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/most_ 4.9.0-2.1_m68k.deb -
Debian 2.2 ppc most_4.9.0-2.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/mo st_4.9.0-2.1_powerpc.deb -
Debian 2.2 sparc most_4.9.0-2.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/most _4.9.0-2.1_sparc.deb