Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
BID:4816
Info
Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 4816 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0910 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Credited to Spybreak <[email protected]>. |
| Vulnerable: |
Debian netstd 3.0 7 |
| Not Vulnerable: | |
Discussion
Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
The netstd package, included with the Debian GNU/Linux distribution, is a collection of networking utilities and daemons. Reportedly, version 3.07 of netstd is vulnerable to a buffer overflow attack. The vulnerability affects multiple utilities included with netstd. The affected utilities are:
- linux-ftpd
- pcnfsd
- tftp
- traceroute
- from/to
The condition is believed to be related to handling of resolved hostnames.
Versions of Debian post-2.2 release do not include this program as a binary package. This program is however distributed as source code through the source tree. Versions pre-2.2 may have to binary package installed.
The netstd package, included with the Debian GNU/Linux distribution, is a collection of networking utilities and daemons. Reportedly, version 3.07 of netstd is vulnerable to a buffer overflow attack. The vulnerability affects multiple utilities included with netstd. The affected utilities are:
- linux-ftpd
- pcnfsd
- tftp
- traceroute
- from/to
The condition is believed to be related to handling of resolved hostnames.
Versions of Debian post-2.2 release do not include this program as a binary package. This program is however distributed as source code through the source tree. Versions pre-2.2 may have to binary package installed.
Exploit / POC
Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
Solution:
Debian versions later than 2.2 do not include this package as a binary. However, the source code for this package is available through the 2.2 source tree. Systems that have installed this package from source are advised to disable all vulnerable services.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian versions later than 2.2 do not include this package as a binary. However, the source code for this package is available through the 2.2 source tree. Systems that have installed this package from source are advised to disable all vulnerable services.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
References:
References: