Mars NWE Buffer Overflow Vulnerabilities
BID:617
Info
Mars NWE Buffer Overflow Vulnerabilities
| Bugtraq ID: | 617 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 31 1999 12:00AM |
| Updated: | Aug 31 1999 12:00AM |
| Credit: | First posted to BugTraq by Przemyslaw Frasunek <[email protected]> in a security advisory on August 31, 1999. |
| Vulnerable: |
Martin Stover Mars NWE 0.99 |
| Not Vulnerable: | |
Discussion
Mars NWE Buffer Overflow Vulnerabilities
There are several buffer overflows in the setuid root components of the Mars Netware Emulator package. They allow for a local root compromise through the overflowing of buffers without bounds checking. It is to be assumed that all versions prior to and including 0.99 are vulnerable to these attacks.
There are several buffer overflows in the setuid root components of the Mars Netware Emulator package. They allow for a local root compromise through the overflowing of buffers without bounds checking. It is to be assumed that all versions prior to and including 0.99 are vulnerable to these attacks.
Exploit / POC
Solution / Fix
Mars NWE Buffer Overflow Vulnerabilities
Solution:
A patch was provided by Przemyslaw Frasunek <[email protected]> in the advisory, along with the exploit. It is available at:
http://www.securityfocus.com/data/vulnerabilities/patches/mars.patch
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
A patch was provided by Przemyslaw Frasunek <[email protected]> in the advisory, along with the exploit. It is available at:
http://www.securityfocus.com/data/vulnerabilities/patches/mars.patch
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].