aria2 'DHTRoutingTableDeserializer::deserialize()' Buffer Overflow Vulnerability
BID:36332
Info
aria2 'DHTRoutingTableDeserializer::deserialize()' Buffer Overflow Vulnerability
| Bugtraq ID: | 36332 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3575 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2009 12:00AM |
| Updated: | Apr 13 2015 10:19PM |
| Credit: | Tatsuhiro Tsujikawa |
| Vulnerable: |
Tatsuhiro Tsujikawa aria2 1.1.2 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Tatsuhiro Tsujikawa aria2 1.2 |
Discussion
aria2 'DHTRoutingTableDeserializer::deserialize()' Buffer Overflow Vulnerability
The 'aria2' program is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data before copying it to insufficiently sized buffers.
Exploiting this issue will allow an attacker to execute arbitrary code in the context of the application, corrupt memory, or cause denial-of-service conditions.
Versions prior to aria2 1.2.0 are vulnerable.
The 'aria2' program is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data before copying it to insufficiently sized buffers.
Exploiting this issue will allow an attacker to execute arbitrary code in the context of the application, corrupt memory, or cause denial-of-service conditions.
Versions prior to aria2 1.2.0 are vulnerable.
Exploit / POC
aria2 'DHTRoutingTableDeserializer::deserialize()' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
aria2 'DHTRoutingTableDeserializer::deserialize()' Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2009.1 x86_64
Mandriva Linux Mandrake 2009.0
Debian Linux 5.0 armel
MandrakeSoft Enterprise Server 5 x86_64
Debian Linux 5.0 alpha
Debian Linux 5.0 amd64
Mandriva Linux Mandrake 2009.0 x86_64
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
MandrakeSoft Enterprise Server 5
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Mandriva Linux Mandrake 2009.1
Debian Linux 5.0 sparc
Tatsuhiro Tsujikawa aria2 1.1.2
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva aria2-1.2.0-0.20090201.3.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva aria2-0.15.3-0.20080918.3.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 armel
-
Debian aria2_0.14.0-1+lenny1_armel.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_armel.deb
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva aria2-0.15.3-0.20080918.3.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 alpha
-
Debian aria2_0.14.0-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_alpha.deb
Debian Linux 5.0 amd64
-
Debian aria2_0.14.0-1+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_amd64.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva aria2-0.15.3-0.20080918.3.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 ia-32
-
Debian aria2_0.14.0-1+lenny1_i386.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_i386.deb
Debian Linux 5.0 mips
-
Debian aria2_0.14.0-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_mips.deb
MandrakeSoft Enterprise Server 5
-
Mandriva aria2-0.15.3-0.20080918.3.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 s/390
-
Debian aria2_0.14.0-1+lenny1_s390.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_s390.deb
Debian Linux 5.0 mipsel
-
Debian aria2_0.14.0-1+lenny1_mipsel.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_mipsel.deb
Mandriva Linux Mandrake 2009.1
-
Mandriva aria2-1.2.0-0.20090201.3.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 sparc
-
Debian aria2_0.14.0-1+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/a/aria2/aria2_0.14.0-1+le nny1_sparc.deb
Tatsuhiro Tsujikawa aria2 1.1.2
-
Tatsuhiro Tsujikawa aria2-1.2.0.tar.bz2
http://sourceforge.net/projects/aria2/files/stable/archives/aria2-1.2. 0/aria2-1.2.0.tar.bz2/download
References
aria2 'DHTRoutingTableDeserializer::deserialize()' Buffer Overflow Vulnerability
References:
References:
- [aria2] Revision 1041 (Tatsuhiro Tsujikawa)
- aria2 Homepage (Tatsuhiro Tsujikawa)
- Bug 52840 �?? buffer overflow in aria2 (Arnaud Patard)