ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability
BID:36574
Info
ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability
| Bugtraq ID: | 36574 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-7224 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2006 12:00AM |
| Updated: | Oct 22 2009 04:48PM |
| Credit: | Jakub Wilk |
| Vulnerable: |
Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server ELinks ELinks 0.11.3 ELinks ELinks 0.11.2 ELinks ELinks 0.11.1 ELinks ELinks 0.10.6 ELinks ELinks 0.10.4 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Aura Application Enablement Services 4.2.1 Avaya AES 4.2.2 Avaya AES 4.2 |
| Not Vulnerable: |
ELinks ELinks 0.11.4 |
Discussion
ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability
ELinks is prone to an off-by-one buffer-overflow vulnerability because the application fails to accurately reference the last element of a buffer.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Versions prior to ELinks 0.11.4 are vulnerable.
ELinks is prone to an off-by-one buffer-overflow vulnerability because the application fails to accurately reference the last element of a buffer.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Versions prior to ELinks 0.11.4 are vulnerable.
Exploit / POC
ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
Ubuntu Ubuntu Linux 6.06 LTS amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Ubuntu Ubuntu Linux 6.06 LTS sparc
Debian Linux 4.0 mipsel
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Debian Linux 4.0 ia-64
Ubuntu Ubuntu Linux 6.06 LTS i386
ELinks ELinks 0.10.4
ELinks ELinks 0.10.6
ELinks ELinks 0.11.1
ELinks ELinks 0.11.2
ELinks ELinks 0.11.3
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian elinks-lite_0.11.1-1.2etch2_amd64.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_amd64.deb -
Debian elinks_0.11.1-1.2etch2_amd64.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_amd64.deb
Ubuntu Ubuntu Linux 6.06 LTS amd64
-
Ubuntu elinks-lite_0.10.6-1ubuntu3.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/e/elinks/elinks-lite_0 .10.6-1ubuntu3.4_amd64.deb -
Ubuntu elinks_0.10.6-1ubuntu3.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/e/elinks/elinks_0.10.6-1ub untu3.4_amd64.deb
Debian Linux 4.0 ia-32
-
Debian elinks-lite_0.11.1-1.2etch2_i386.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_i386.deb -
Debian elinks_0.11.1-1.2etch2_i386.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_i386.deb
Debian Linux 4.0 arm
-
Debian elinks-lite_0.11.1-1.2etch2_arm.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_arm.deb -
Debian elinks_0.11.1-1.2etch2_arm.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_arm.deb
Debian Linux 4.0 hppa
-
Debian elinks-lite_0.11.1-1.2etch2_hppa.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_hppa.deb -
Debian elinks_0.11.1-1.2etch2_hppa.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_hppa.deb
Debian Linux 4.0 sparc
-
Debian elinks-lite_0.11.1-1.2etch2_sparc.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_sparc.deb -
Debian elinks_0.11.1-1.2etch2_sparc.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_sparc.deb
Debian Linux 4.0 s/390
-
Debian elinks-lite_0.11.1-1.2etch2_s390.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_s390.deb -
Debian elinks_0.11.1-1.2etch2_s390.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_s390.deb
Debian Linux 4.0 powerpc
-
Debian elinks-lite_0.11.1-1.2etch2_powerpc.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_powerpc.deb -
Debian elinks_0.11.1-1.2etch2_powerpc.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_powerpc.deb
Debian Linux 4.0 alpha
-
Debian elinks-lite_0.11.1-1.2etch2_alpha.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_alpha.deb -
Debian elinks_0.11.1-1.2etch2_alpha.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_alpha.deb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu elinks-lite_0.10.6-1ubuntu3.4_sparc.deb
http://security.ubuntu.com/ubuntu/pool/universe/e/elinks/elinks-lite_0 .10.6-1ubuntu3.4_sparc.deb -
Ubuntu elinks_0.10.6-1ubuntu3.4_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/e/elinks/elinks_0.10.6-1ub untu3.4_sparc.deb
Debian Linux 4.0 mipsel
-
Debian elinks-lite_0.11.1-1.2etch2_mipsel.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_mipsel.deb -
Debian elinks_0.11.1-1.2etch2_mipsel.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_mipsel.deb
Ubuntu Ubuntu Linux 6.06 LTS powerpc
-
Ubuntu elinks-lite_0.10.6-1ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/universe/e/elinks/elinks-lite_0 .10.6-1ubuntu3.4_powerpc.deb -
Ubuntu elinks_0.10.6-1ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/e/elinks/elinks_0.10.6-1ub untu3.4_powerpc.deb
Debian Linux 4.0 ia-64
-
Debian elinks-lite_0.11.1-1.2etch2_ia64.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks-lite_0.11 .1-1.2etch2_ia64.deb -
Debian elinks_0.11.1-1.2etch2_ia64.deb
http://security.debian.org/pool/updates/main/e/elinks/elinks_0.11.1-1. 2etch2_ia64.deb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu elinks-lite_0.10.6-1ubuntu3.4_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/e/elinks/elinks-lite_0 .10.6-1ubuntu3.4_i386.deb -
Ubuntu elinks_0.10.6-1ubuntu3.4_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/e/elinks/elinks_0.10.6-1ub untu3.4_i386.deb
ELinks ELinks 0.10.4
-
ELinks elinks-0.11.4rc0.tar.gz
http://elinks.or.cz/download/elinks-0.11.4rc0.tar.gz
ELinks ELinks 0.10.6
-
ELinks elinks-0.11.4rc0.tar.gz
http://elinks.or.cz/download/elinks-0.11.4rc0.tar.gz
ELinks ELinks 0.11.1
-
ELinks elinks-0.11.4rc0.tar.gz
http://elinks.or.cz/download/elinks-0.11.4rc0.tar.gz
ELinks ELinks 0.11.2
-
ELinks elinks-0.11.4rc0.tar.gz
http://elinks.or.cz/download/elinks-0.11.4rc0.tar.gz
ELinks ELinks 0.11.3
-
ELinks elinks-0.11.4rc0.tar.gz
http://elinks.or.cz/download/elinks-0.11.4rc0.tar.gz
References
ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability
References:
References:
- [elinks-users] [ANNOUNCE] ELinks 0.11.4rc0 (ELink)
- Elinks Home Page (Elinks)
- elinks: crashes on a specially crafted page (Jakub Wilk)
- ASA-2009-448 (Avaya)