Debian Super Syslog Buffer Overflow Vulnerability
BID:342
Info
Debian Super Syslog Buffer Overflow Vulnerability
| Bugtraq ID: | 342 |
| Class: | Unknown |
| CVE: |
CVE-1999-0381 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 25 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | First posted to BugTraq by c0nd0r <[email protected]> on February 25, 1999. |
| Vulnerable: |
Debian Linux 2.0 |
| Not Vulnerable: | |
Discussion
Debian Super Syslog Buffer Overflow Vulnerability
After the first super buffer overflow vulnerability was discovered, another appeared shortly after. This vulnerability exists when the syslog option is enabled. The overflow is in the file error.c, in the Error() function where the buf[MAXPRINT] buffer is used with no bounds checking. The consequences of this are local root compromise.
After the first super buffer overflow vulnerability was discovered, another appeared shortly after. This vulnerability exists when the syslog option is enabled. The overflow is in the file error.c, in the Error() function where the buf[MAXPRINT] buffer is used with no bounds checking. The consequences of this are local root compromise.
References
Debian Super Syslog Buffer Overflow Vulnerability
References:
References: