DayDream BBS Control Code Multiple Buffer Overflow Vulnerability

BID:3757

Info

DayDream BBS Control Code Multiple Buffer Overflow Vulnerability

Bugtraq ID: 3757
Class: Boundary Condition Error
CVE: CVE-2001-1207
Remote: Yes
Local: No
Published: Dec 30 2001 12:00AM
Updated: Jul 12 2009 05:56PM
Credit: Reported by KF <[email protected]> in a posting to the BugTraq mailing list on December 30, 2001.
Vulnerable: DayDream DayDream BBS 2.13
DayDream DayDream BBS 2.12
DayDream DayDream BBS 2.10
DayDream DayDream BBS 2.9
Not Vulnerable:

Discussion

DayDream BBS Control Code Multiple Buffer Overflow Vulnerability

DayDream BBS was originally written for AmigaOS, although a port is now actively maintained for Linux and BSD based systems. DayDream is conference based, and includes support for message boards, file transfers, and doors.

DayDream supports control codes included in text files, which are used to insert additional information and to perform some actions. Some of these control codes can lead to buffer overflows when they are passed extremely large parameters. This may lead to the execution of arbitrary code.

If a user is able to include these control codes in posted messages, it may be possible for a remote user of the BBS system to cause arbitrary code to be executed. Under the recommended installation, this will be as the non-privileged user 'bbs'.

Exploit / POC

DayDream BBS Control Code Multiple Buffer Overflow Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] &lt;mailto:[email protected]&gt;.

Solution / Fix

DayDream BBS Control Code Multiple Buffer Overflow Vulnerability

Solution:
There have been reports that this vulnerability is fixed in the most recent release of DayDream BBS.

References

DayDream BBS Control Code Multiple Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report