Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
BID:5125
Info
Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 5125 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 29 2002 12:00AM |
| Updated: | Jun 29 2002 12:00AM |
| Credit: | Vulnerability discovery credited to <[email protected]>. |
| Vulnerable: |
Slackware Linux 8.0 Redhat Linux 7.1 ia64 Redhat Linux 7.1 i386 Redhat Linux 7.1 alpha Redhat Linux 7.0 sparc Redhat Linux 7.0 i386 Redhat Linux 7.0 alpha Redhat Linux 6.2 sparc Redhat Linux 6.2 i386 Redhat Linux 6.2 alpha Mandriva Linux Mandrake 9.0 Mandriva Linux Mandrake 8.0 ppc Mandriva Linux Mandrake 8.0 Mandriva Linux Mandrake 7.1 |
| Not Vulnerable: | |
Discussion
Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
Bonobo is a set of tools and CORBA interfaces included as part of the Gnome infrastructure. It is designed for use on the Linux and Unix operating systems.
A boundry condition error has been discovered in the efstool program. Due to improper bounds checking, it is possible for a user to supply a long commandline argument to the efstool program, which would result in a buffer overflow. This problem could be exploited on the local system to overwrite stack memory, including the return address, and execute attacker supplied code.
Bonobo is a set of tools and CORBA interfaces included as part of the Gnome infrastructure. It is designed for use on the Linux and Unix operating systems.
A boundry condition error has been discovered in the efstool program. Due to improper bounds checking, it is possible for a user to supply a long commandline argument to the efstool program, which would result in a buffer overflow. This problem could be exploited on the local system to overwrite stack memory, including the return address, and execute attacker supplied code.
Exploit / POC
Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
Exploit contributed by <[email protected]>.
Additional exploit contributed by Andrea Lisci. efstool-expl.c supplied by N4rK07IX.
Exploit contributed by <[email protected]>.
Additional exploit contributed by Andrea Lisci. efstool-expl.c supplied by N4rK07IX.
Solution / Fix
Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
References:
References:
- Bonobo Homepage (Gnome)