BannerWheel Remote Buffer Overflow Vulnerability
BID:4782
Info
BannerWheel Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 4782 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2002 12:00AM |
| Updated: | May 20 2002 12:00AM |
| Credit: | Discovery of this issue is credited to <[email protected]>. |
| Vulnerable: |
BannerWheel BannerWheel 1.0 |
| Not Vulnerable: | |
Discussion
BannerWheel Remote Buffer Overflow Vulnerability
BannerWheel is a freely available ad banner rotation program. It runs on most Unix and Linux variants as well as Microsoft Windows operating systems.
Due to insufficient bounds checking of externally supplied data, BannerWheel may be prone to a buffer overflow condition.
If exploitable, this condition may allow a remote attacker to execute arbitrary instructions with the privileges of the webserver process.
BannerWheel is a freely available ad banner rotation program. It runs on most Unix and Linux variants as well as Microsoft Windows operating systems.
Due to insufficient bounds checking of externally supplied data, BannerWheel may be prone to a buffer overflow condition.
If exploitable, this condition may allow a remote attacker to execute arbitrary instructions with the privileges of the webserver process.
Exploit / POC
BannerWheel Remote Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BannerWheel Remote Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.