DayDream BBS Control Code Multiple Buffer Overflow Vulnerability
BID:3757
Info
DayDream BBS Control Code Multiple Buffer Overflow Vulnerability
| Bugtraq ID: | 3757 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1207 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2001 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Reported by KF <[email protected]> in a posting to the BugTraq mailing list on December 30, 2001. |
| Vulnerable: |
DayDream DayDream BBS 2.13 DayDream DayDream BBS 2.12 DayDream DayDream BBS 2.10 DayDream DayDream BBS 2.9 |
| Not Vulnerable: | |
Discussion
DayDream BBS Control Code Multiple Buffer Overflow Vulnerability
DayDream BBS was originally written for AmigaOS, although a port is now actively maintained for Linux and BSD based systems. DayDream is conference based, and includes support for message boards, file transfers, and doors.
DayDream supports control codes included in text files, which are used to insert additional information and to perform some actions. Some of these control codes can lead to buffer overflows when they are passed extremely large parameters. This may lead to the execution of arbitrary code.
If a user is able to include these control codes in posted messages, it may be possible for a remote user of the BBS system to cause arbitrary code to be executed. Under the recommended installation, this will be as the non-privileged user 'bbs'.
DayDream BBS was originally written for AmigaOS, although a port is now actively maintained for Linux and BSD based systems. DayDream is conference based, and includes support for message boards, file transfers, and doors.
DayDream supports control codes included in text files, which are used to insert additional information and to perform some actions. Some of these control codes can lead to buffer overflows when they are passed extremely large parameters. This may lead to the execution of arbitrary code.
If a user is able to include these control codes in posted messages, it may be possible for a remote user of the BBS system to cause arbitrary code to be executed. Under the recommended installation, this will be as the non-privileged user 'bbs'.
Exploit / POC
DayDream BBS Control Code Multiple Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
DayDream BBS Control Code Multiple Buffer Overflow Vulnerability
Solution:
There have been reports that this vulnerability is fixed in the most recent release of DayDream BBS.
Solution:
There have been reports that this vulnerability is fixed in the most recent release of DayDream BBS.
References
DayDream BBS Control Code Multiple Buffer Overflow Vulnerability
References:
References:
- DayDream BBS Homepage (DayDream)