Network Block Device Server (CVE-2011-0530) Remote Buffer Overflow Vulnerability
BID:46572
Info
Network Block Device Server (CVE-2011-0530) Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 46572 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-0530 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2011 12:00AM |
| Updated: | Jun 25 2012 11:10PM |
| Credit: | Wouter Verhelst |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise 10 SP4 SuSE SUSE Linux Enterprise 10 SP3 SuSE openSUSE 11.4 SuSE openSUSE 11.3 S.u.S.E. openSUSE 11.2 Network Block Device NBD 2.9.0 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
Network Block Device Server (CVE-2011-0530) Remote Buffer Overflow Vulnerability
Network Block Device Server is prone to a remote buffer-overflow vulnerability.
Attackers may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Network Block Device 2.9.0 is vulnerable.
Note: This issue was fixed in version 2.8.3 (CVE-2005-3534) and reintroduced again in version 2.9.0.
Network Block Device Server is prone to a remote buffer-overflow vulnerability.
Attackers may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Network Block Device 2.9.0 is vulnerable.
Note: This issue was fixed in version 2.8.3 (CVE-2005-3534) and reintroduced again in version 2.9.0.
Exploit / POC
Network Block Device Server (CVE-2011-0530) Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Network Block Device Server (CVE-2011-0530) Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Network Block Device Server (CVE-2011-0530) Remote Buffer Overflow Vulnerability
References:
References:
- CVE Request -- NDB: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version (headers Jan Lieskovsky)
- GIT Commit (Wouter Verhelst)
- NBD Homepage (Network Block Device)