mnoGoSearch 3.1.19 Search Query Buffer Overflow Vulnerability
BID:4724
Info
mnoGoSearch 3.1.19 Search Query Buffer Overflow Vulnerability
| Bugtraq ID: | 4724 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2002 12:00AM |
| Updated: | May 11 2002 12:00AM |
| Credit: | Posted to BugTraq on May 11, 2002 by qitest1 <[email protected]> |
| Vulnerable: |
mnoGoSearch mnoGoSearch 3.1.19 |
| Not Vulnerable: | |
Discussion
mnoGoSearch 3.1.19 Search Query Buffer Overflow Vulnerability
mnoGoSearch 3.1.19 is an SQL based search engine. It is vulnerable to a buffer overflow condition. A long string can be submitted to the search.cgi script as a search query. This is potentially exploitable to execute code on the host machine.
mnoGoSearch 3.1.19 is an SQL based search engine. It is vulnerable to a buffer overflow condition. A long string can be submitted to the search.cgi script as a search query. This is potentially exploitable to execute code on the host machine.
Exploit / POC
mnoGoSearch 3.1.19 Search Query Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
mnoGoSearch 3.1.19 Search Query Buffer Overflow Vulnerability
Solution:
Conectiva has released a security advisory (CLA-2003:711) and fixes to address this issue. Details regarding applying fixes can be found in the referenced advisory, fixes are linked below.
This is reportedly fixed in the latest cvs version.
mnoGoSearch mnoGoSearch 3.1.19
Solution:
Conectiva has released a security advisory (CLA-2003:711) and fixes to address this issue. Details regarding applying fixes can be found in the referenced advisory, fixes are linked below.
This is reportedly fixed in the latest cvs version.
mnoGoSearch mnoGoSearch 3.1.19
-
Conectiva mnogosearch-3.1.21-12434U90_2cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/mnogosearch-3.1.21-12434U90 _2cl.i386.rpm -
Conectiva mnogosearch-3.1.21-12434U90_2cl.src.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/SRPMS/mnogosearch-3.1.21-12434U9 0_2cl.src.rpm -
Conectiva mnogosearch-devel-3.1.21-12434U90_2cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/mnogosearch-devel-3.1.21-12 434U90_2cl.i386.rpm -
Conectiva mnogosearch-devel-static-3.1.21-12434U90_2cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/mnogosearch-devel-static-3. 1.21-12434U90_2cl.i386.rpm
References
mnoGoSearch 3.1.19 Search Query Buffer Overflow Vulnerability
References:
References:
- mnoGoSearch Homepage (mnoGoSearch)