CFS Multiple Buffer Overflow Vulnerabilities
BID:4219
Info
CFS Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 4219 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0351 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Debian credits "Zorgon" with discovery (DSA-116-1). |
| Vulnerable: |
Matt Blaze cfs 1.3.3 Sparc Matt Blaze cfs 1.3.3 PPC Matt Blaze cfs 1.3.3 m68k Matt Blaze cfs 1.3.3 ia32 Matt Blaze cfs 1.3.3 ARM Matt Blaze cfs 1.3.3 Alpha Matt Blaze cfs 1.3.3 |
| Not Vulnerable: |
Matt Blaze cfs 1.4.1 -5 Matt Blaze cfs 1.3.3 -8.1 Sparc Matt Blaze cfs 1.3.3 -8.1 PPC Matt Blaze cfs 1.3.3 -8.1 m68k Matt Blaze cfs 1.3.3 -8.1 ia32 Matt Blaze cfs 1.3.3 -8.1 ARM Matt Blaze cfs 1.3.3 -8.1 Alpha Matt Blaze cfs 1.3.3 -8.1 |
Discussion
CFS Multiple Buffer Overflow Vulnerabilities
Cryptographic File System (CFS) for Unix is a file system encryption package. Versions prior to 1.3.3-8.1 are vulnerable to a number of buffer overflow issues. Whether or not these are exploitable to obtain privileges on the host is unknown at the present time. They can be used to initiate a denial of service condition against the encrypted file system, however.
Cryptographic File System (CFS) for Unix is a file system encryption package. Versions prior to 1.3.3-8.1 are vulnerable to a number of buffer overflow issues. Whether or not these are exploitable to obtain privileges on the host is unknown at the present time. They can be used to initiate a denial of service condition against the encrypted file system, however.
Exploit / POC
CFS Multiple Buffer Overflow Vulnerabilities
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CFS Multiple Buffer Overflow Vulnerabilities
Solution:
Debian has provided fixed packages.
Matt Blaze cfs 1.3.3
Matt Blaze cfs 1.3.3 PPC
Matt Blaze cfs 1.3.3 m68k
Matt Blaze cfs 1.3.3 Alpha
Matt Blaze cfs 1.3.3 ia32
Matt Blaze cfs 1.3.3 Sparc
Matt Blaze cfs 1.3.3 ARM
Solution:
Debian has provided fixed packages.
Matt Blaze cfs 1.3.3
-
Debian cfs_1.3.3-8.1.diff.gz
http://security.debian.org/dists/stable/updates/main/source/cfs_1.3.3- 8.1.diff.gz -
Debian cfs_1.3.3.orig.tar.gz
http://security.debian.org/dists/stable/updates/main/source/cfs_1.3.3. orig.tar.gz
Matt Blaze cfs 1.3.3 PPC
-
Debian cfs_1.3.3-8.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/cf s_1.3.3-8.1_powerpc.deb
Matt Blaze cfs 1.3.3 m68k
-
Debian cfs_1.3.3-8.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/cfs_1 .3.3-8.1_m68k.deb
Matt Blaze cfs 1.3.3 Alpha
-
Debian cfs_1.3.3-8.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/cfs_ 1.3.3-8.1_alpha.deb
Matt Blaze cfs 1.3.3 ia32
-
Debian cfs_1.3.3-8.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/cfs_1 .3.3-8.1_i386.deb
Matt Blaze cfs 1.3.3 Sparc
-
Debian cfs_1.3.3-8.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/cfs_ 1.3.3-8.1_sparc.deb
Matt Blaze cfs 1.3.3 ARM
-
Debian cfs_1.3.3-8.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/cfs_1. 3.3-8.1_arm.deb
References
CFS Multiple Buffer Overflow Vulnerabilities
References:
References:
- A Cryptographic File System for Unix (Matt Blaze)