ISC INN Multiple Insecure Open Call Vulnerabilities
BID:6049
Info
ISC INN Multiple Insecure Open Call Vulnerabilities
| Bugtraq ID: | 6049 |
| Class: | Design Error |
| CVE: |
CVE-2002-0526 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 11 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovered by Paul Starzetz <[email protected]>. |
| Vulnerable: |
ISC INN 2.2.3 ISC INN 2.2.2 ISC INN 2.2.1 ISC INN 2.2 ISC INN 2.1 ISC INN 2.0 |
| Not Vulnerable: |
ISC INN 2.3.3 |
Discussion
ISC INN Multiple Insecure Open Call Vulnerabilities
The Internet Software Consortium (ISC) Internet News (INN) project is a powerful, mature implementation of a usenet system, including a NNTP server and a newsreading server. It is available for a wide range of Unix based systems, including Linux.
Multiple vulnerabilities have been reported in two components of INN, inews and rnews. Reportedly, both are vulnerable to insecure open() calls in some binaries included with INN. Further details are not currently available.
The Internet Software Consortium (ISC) Internet News (INN) project is a powerful, mature implementation of a usenet system, including a NNTP server and a newsreading server. It is available for a wide range of Unix based systems, including Linux.
Multiple vulnerabilities have been reported in two components of INN, inews and rnews. Reportedly, both are vulnerable to insecure open() calls in some binaries included with INN. Further details are not currently available.
Exploit / POC
ISC INN Multiple Insecure Open Call Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.