Progress Database Malicious ProTermCap File Buffer Overflow Vulnerability
BID:3414
Info
Progress Database Malicious ProTermCap File Buffer Overflow Vulnerability
| Bugtraq ID: | 3414 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1128 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 09 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was announced by KF <[email protected]> via Bugtraq on October 9, 2001. |
| Vulnerable: |
Progress Database 9.1 C Progress Database 9.1 B Progress Database 8.3 D |
| Not Vulnerable: |
Progress Database 9.1 C Progress Database 8.3 E |
Discussion
Progress Database Malicious ProTermCap File Buffer Overflow Vulnerability
Progress is a database software implementation distributed by Progress Software.
A problem with the software could make it possible for a local user to execute arbitrary code. This could present problems in setuid installations. The problem is due to the handling of long entries in the protermcap file. A malicious protermcap file with a 9000 character entry could be created, and loaded via the PROTERMCAP oe PROMSGS environment variable. Upon execution of Progress, it would result in the execution of arbitrary code from a local user.
Progress is a database software implementation distributed by Progress Software.
A problem with the software could make it possible for a local user to execute arbitrary code. This could present problems in setuid installations. The problem is due to the handling of long entries in the protermcap file. A malicious protermcap file with a 9000 character entry could be created, and loaded via the PROTERMCAP oe PROMSGS environment variable. Upon execution of Progress, it would result in the execution of arbitrary code from a local user.
Exploit / POC
Progress Database Malicious ProTermCap File Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Progress Database Malicious ProTermCap File Buffer Overflow Vulnerability
Solution:
Reported fixed in versions 8.3E, 9.1C.
Solution:
Reported fixed in versions 8.3E, 9.1C.
References
Progress Database Malicious ProTermCap File Buffer Overflow Vulnerability
References:
References: