Boozt! Buffer Overflow Vulnerability
BID:3787
Info
Boozt! Buffer Overflow Vulnerability
| Bugtraq ID: | 3787 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2002 12:00AM |
| Updated: | Jan 07 2002 12:00AM |
| Credit: | Discovered and posted to Bugtraq by [email protected]. |
| Vulnerable: |
Boozt! Boozt! Standard 0.9.8 |
| Not Vulnerable: |
Boozt! Boozt! Standard 0.9.9 |
Discussion
Boozt! Buffer Overflow Vulnerability
Boozt! is a free open source banner management software for Linux hosts.
An issue has been reported which could allow for a user to execute arbitrary code on a Boozt! host.
This is acheivable when a Boozt! user attempts to create a new banner, if the name field is specified with arbitrary characters of excessive length a buffer overflow occurs.
Boozt! is a free open source banner management software for Linux hosts.
An issue has been reported which could allow for a user to execute arbitrary code on a Boozt! host.
This is acheivable when a Boozt! user attempts to create a new banner, if the name field is specified with arbitrary characters of excessive length a buffer overflow occurs.
Exploit / POC
Boozt! Buffer Overflow Vulnerability
Rafael San Miguel Carrasco <[email protected]> has provided the following exploit:
Rafael San Miguel Carrasco <[email protected]> has provided the following exploit:
Solution / Fix
Boozt! Buffer Overflow Vulnerability
Solution:
Boozt! Standard 0.9.9 has been released to address this issue. Users are encouraged to upgrade.
http://www.boozt.com/news_detail.php?id=3
Solution:
Boozt! Standard 0.9.9 has been released to address this issue. Users are encouraged to upgrade.
http://www.boozt.com/news_detail.php?id=3
References
Boozt! Buffer Overflow Vulnerability
References:
References:
- Boozt! Fix Information (Boozt!)
- Boozt! Homepage (Boozt!)