Libsafe Format String Unimplemented Specifier Exploitation Vulnerability
BID:4326
Info
Libsafe Format String Unimplemented Specifier Exploitation Vulnerability
| Bugtraq ID: | 4326 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 20 2002 12:00AM |
| Updated: | Mar 20 2002 12:00AM |
| Credit: | This vulnerability discovery is credited to Wojciech Purczynski <[email protected]>. |
| Vulnerable: |
Avaya Labs Libsafe 2.0 -9 Avaya Labs Libsafe 2.0 -5 Avaya Labs Libsafe 2.0 -2 Avaya Labs Libsafe 2.0 -11 Avaya Labs Libsafe 2.0 -10 Avaya Labs Libsafe 1.3 -8 Avaya Labs Libsafe 1.3 -4 |
| Not Vulnerable: |
Avaya Labs Libsafe 2.0 -12 |
Discussion
Libsafe Format String Unimplemented Specifier Exploitation Vulnerability
Libsafe is a freely available, open source software package distributed and maintained by Avaya Labs. It is designed to act as a prophylactic measure against buffer overflow and format string attacks on Linux systems.
Under some circumstances, checks performed by the libsafe suite may be bypassed. This is due to the lack of implementation of some format specifier types in Libsafe. C library format specifiers "%'n" and "%In" are not implemented in Libsafe, and can therefore allow exploitation of format string vulnerabilities in which these specifiers are not correctly used.
Libsafe is a freely available, open source software package distributed and maintained by Avaya Labs. It is designed to act as a prophylactic measure against buffer overflow and format string attacks on Linux systems.
Under some circumstances, checks performed by the libsafe suite may be bypassed. This is due to the lack of implementation of some format specifier types in Libsafe. C library format specifiers "%'n" and "%In" are not implemented in Libsafe, and can therefore allow exploitation of format string vulnerabilities in which these specifiers are not correctly used.
Exploit / POC
Libsafe Format String Unimplemented Specifier Exploitation Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Libsafe Format String Unimplemented Specifier Exploitation Vulnerability
Solution:
A fixed version is available:
Avaya Labs Libsafe 1.3 -4
Avaya Labs Libsafe 1.3 -8
Avaya Labs Libsafe 2.0 -11
Avaya Labs Libsafe 2.0 -5
Avaya Labs Libsafe 2.0 -10
Avaya Labs Libsafe 2.0 -2
Avaya Labs Libsafe 2.0 -9
Solution:
A fixed version is available:
Avaya Labs Libsafe 1.3 -4
-
Avaya Labs libsafe-2.0-12.tgz
http://www.research.avayalabs.com/project/libsafe/src/libsafe-2.0-12.t gz -
MandrakeSoft libsafe-2.0.13-1.2mdk.i586.rpm
for Linux-Mandrake 7.1
http://www.mandrakesecure.net/en/ftp.php
Avaya Labs Libsafe 1.3 -8
-
Avaya Labs libsafe-2.0-12.tgz
http://www.research.avayalabs.com/project/libsafe/src/libsafe-2.0-12.t gz -
MandrakeSoft libsafe-2.0.13-1.2mdk.i586.rpm
for Corporate Server 1.0.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft libsafe-2.0.13-1.2mdk.i586.rpm
for Linux-Mandrake 7.2.
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft libsafe-2.0.13-1.2mdk.i586.rpm
for Single Network Firewall 7.2
http://www.mandrakesecure.net/en/ftp.php
Avaya Labs Libsafe 2.0 -11
-
Avaya Labs libsafe-2.0-12.tgz
http://www.research.avayalabs.com/project/libsafe/src/libsafe-2.0-12.t gz
Avaya Labs Libsafe 2.0 -5
-
Avaya Labs libsafe-2.0-12.tgz
http://www.research.avayalabs.com/project/libsafe/src/libsafe-2.0-12.t gz -
MandrakeSoft libsafe-2.0.13-1.2mdk.i586.rpm
for Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft libsafe-2.0.13-1.2mdk.i586.rpm
for Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php
Avaya Labs Libsafe 2.0 -10
-
Avaya Labs libsafe-2.0-12.tgz
http://www.research.avayalabs.com/project/libsafe/src/libsafe-2.0-12.t gz
Avaya Labs Libsafe 2.0 -2
-
Avaya Labs libsafe-2.0-12.tgz
http://www.research.avayalabs.com/project/libsafe/src/libsafe-2.0-12.t gz -
MandrakeSoft libsafe-2.0.13-1.2mdk.i586.rpm
for Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php
Avaya Labs Libsafe 2.0 -9
-
Avaya Labs libsafe-2.0-12.tgz
http://www.research.avayalabs.com/project/libsafe/src/libsafe-2.0-12.t gz
References
Libsafe Format String Unimplemented Specifier Exploitation Vulnerability
References:
References:
- Libsafe Project Page (Avaya Labs)