Bradford Barrett Webalizer Reverse DNS Buffer Overflow Vulnerability
BID:4504
Info
Bradford Barrett Webalizer Reverse DNS Buffer Overflow Vulnerability
| Bugtraq ID: | 4504 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0180 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by Spybreak <[email protected]>. |
| Vulnerable: |
Bradford Barrett Webalizer 2.0.1 -09 Bradford Barrett Webalizer 2.0.1 -06 Bradford Barrett Webalizer 2.0.1 -04 Bradford Barrett Webalizer 2.0.1 -01 Bradford Barrett Webalizer 1.30 -04 |
| Not Vulnerable: |
Bradford Barrett Webalizer 2.0.1 -10 |
Discussion
Bradford Barrett Webalizer Reverse DNS Buffer Overflow Vulnerability
Webalizer is a web server log file program, which generates web site statistic log files. Log files produced include referrer information, browser information, web site Hits, Files accessed etc. These log files are generated in HTML format, so administrators can view them in a web browser.
A remote buffer overflow vulnerability has been reported in some versions of Webalizer. A malicious DNS server may exploit this condition if reverse DNS lookups are enabled.
The vendor has reported that this vulnerability is not exploitable for code execution, due to both memory layout of the process and character restrictions on the injected data. However some denial of service attacks may be possible.
Webalizer is a web server log file program, which generates web site statistic log files. Log files produced include referrer information, browser information, web site Hits, Files accessed etc. These log files are generated in HTML format, so administrators can view them in a web browser.
A remote buffer overflow vulnerability has been reported in some versions of Webalizer. A malicious DNS server may exploit this condition if reverse DNS lookups are enabled.
The vendor has reported that this vulnerability is not exploitable for code execution, due to both memory layout of the process and character restrictions on the injected data. However some denial of service attacks may be possible.
Exploit / POC
Bradford Barrett Webalizer Reverse DNS Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Bradford Barrett Webalizer Reverse DNS Buffer Overflow Vulnerability
Solution:
Updated versions are available:
Bradford Barrett Webalizer 1.30 -04
Bradford Barrett Webalizer 2.0.1 -04
Bradford Barrett Webalizer 2.0.1 -01
Bradford Barrett Webalizer 2.0.1 -09
Bradford Barrett Webalizer 2.0.1 -06
Solution:
Updated versions are available:
Bradford Barrett Webalizer 1.30 -04
-
Conectiva webalizer-2.01.10-4U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/webalizer-2.01.10-4U50_1c l.i386.rpm -
Conectiva webalizer-2.01.10-4U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/webalizer-2.01.10-4U51_1c l.i386.rpm -
Conectiva webalizer-2.01.10-4U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/webalizer-2.01.10-4U60_1c l.i386.rpm -
Conectiva webalizer-doc-2.01.10-4U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/webalizer-doc-2.01.10-4U5 0_1cl.i386.rpm -
Conectiva webalizer-doc-2.01.10-4U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/webalizer-doc-2.01.10-4U5 1_1cl.i386.rpm -
Conectiva webalizer-doc-2.01.10-4U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/webalizer-doc-2.01.10-4U6 0_1cl.i386.rpm
Bradford Barrett Webalizer 2.0.1 -04
-
Conectiva webalizer-2.01.10-4U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/webalizer-2.01.10-4U70_1c l.i386.rpm -
Conectiva webalizer-2.01.10-4U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/webalizer-2.01.10-4U8_1cl.i 386.rpm -
Conectiva webalizer-doc-2.01.10-4U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/webalizer-doc-2.01.10-4U7 0_1cl.i386.rpm -
Conectiva webalizer-doc-2.01.10-4U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/webalizer-doc-2.01.10-4U8_1 cl.i386.rpm
Bradford Barrett Webalizer 2.0.1 -01
-
EnGarde Secure Linux webalizer-2.01-1.0.4.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i386/webalizer-2 .01-1.0.4.i386.rpm -
EnGarde Secure Linux webalizer-2.01-1.0.4.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i686/webalizer-2 .01-1.0.4.i686.rpm
Bradford Barrett Webalizer 2.0.1 -09
-
Bradford Barrett webalizer-2.01-10-src.tgz
ftp://ftp.mrunix.net/pub/webalizer/webalizer-2.01-10-src.tgz -
FreeBSD webalizer-2.1.10_1.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/All/web alizer-2.1.10_1.tgz -
SCO webalizer-2.01_09-2.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-036.0/R PMS/webalizer-2.01_09-2.i386.rpm -
SCO webalizer-2.01_09-2.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-036.0/RPM S/webalizer-2.01_09-2.i386.rpm
Bradford Barrett Webalizer 2.0.1 -06
-
Bradford Barrett webalizer-2.01-10-src.tgz
ftp://ftp.mrunix.net/pub/webalizer/webalizer-2.01-10-src.tgz -
RedHat webalizer-2.01_09-1.72.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/webalizer-2.01_09-1.72.i386.rp m -
RedHat webalizer-2.01_09-1.72.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/webalizer-2.01_09-1.72.ia64.rp m
References
Bradford Barrett Webalizer Reverse DNS Buffer Overflow Vulnerability
References:
References:
- Webalizer Homepage (Bradford Barrett )