tinc CVE-2013-1428 Stack Buffer Overflow Vulnerability
BID:59369
Info
tinc CVE-2013-1428 Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 59369 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-1428 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2013 12:00AM |
| Updated: | Apr 13 2015 09:29PM |
| Credit: | Martin Schobert |
| Vulnerable: |
tinc tinc 1.0.20 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
tinc tinc 1.0.21 |
Discussion
tinc CVE-2013-1428 Stack Buffer Overflow Vulnerability
tinc is prone to a stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts may crash the application, denying service to legitimate users.
tinc is prone to a stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts may crash the application, denying service to legitimate users.
Exploit / POC
tinc CVE-2013-1428 Stack Buffer Overflow Vulnerability
The following metasploit exploit code is available:
The following metasploit exploit code is available:
Solution / Fix
tinc CVE-2013-1428 Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
tinc CVE-2013-1428 Stack Buffer Overflow Vulnerability
References:
References:
- tinc 1.0.21 released (tinc)
- tinc HomePage (tinc)