fnord Web Server Buffer Overflow Vulnerability
BID:6635
Info
fnord Web Server Buffer Overflow Vulnerability
| Bugtraq ID: | 6635 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2003 12:00AM |
| Updated: | Jan 17 2003 12:00AM |
| Credit: | This vulnerability was reported in the product changelog. |
| Vulnerable: |
fnord fnord 1.6 |
| Not Vulnerable: |
fnord fnord 1.7 |
Discussion
fnord Web Server Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for fnord. The vulnerability exists in the httpd.c source file and is due to insufficient bounds checking when performing CGI operations.
Reportedly, a buffer is allocated a space in memory that is too small. A determined attacker is able to exploit this vulnerability by making an overly long CGI request to the web server.
This will trigger the buffer overflow condition and may cause the web server to behave erratically.
A buffer overflow vulnerability has been reported for fnord. The vulnerability exists in the httpd.c source file and is due to insufficient bounds checking when performing CGI operations.
Reportedly, a buffer is allocated a space in memory that is too small. A determined attacker is able to exploit this vulnerability by making an overly long CGI request to the web server.
This will trigger the buffer overflow condition and may cause the web server to behave erratically.
Exploit / POC
fnord Web Server Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
fnord Web Server Buffer Overflow Vulnerability
Solution:
Gentoo Linux has released an advisory. Users who have installed net-www/fnord are advised to upgrade their systems to fnord-1.7 by issuing the following commands:
emerge sync
emerge -u fnord
emerge clean
Fixes available:
fnord fnord 1.6
Solution:
Gentoo Linux has released an advisory. Users who have installed net-www/fnord are advised to upgrade their systems to fnord-1.7 by issuing the following commands:
emerge sync
emerge -u fnord
emerge clean
Fixes available:
fnord fnord 1.6
-
fnord fnord-1.7.tar.bz2
http://www.fefe.de/fnord/fnord-1.7.tar.bz2