Linux-ATM LES Command Line Argument Buffer Overflow Vulnerability
BID:7437
Info
Linux-ATM LES Command Line Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 7437 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0396 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 25 2003 12:00AM |
| Updated: | Jul 11 2009 09:07PM |
| Credit: | Discovery of this vulnerability has been credited to Angelo Rosiello. |
| Vulnerable: |
linux-atm les 2.4 |
| Not Vulnerable: | |
Discussion
Linux-ATM LES Command Line Argument Buffer Overflow Vulnerability
The linux-atm 'les' executable has been reported prone to a buffer overflow vulnerability.
This issue is due to a lack of sufficient bounds checking performed on data supplied via specific command line arguments to the 'les' executable. Excessive data may overrun the bounds of an internal memory buffer and corrupt adjacent memory. As a direct result of this issue arbitrary code execution is possible.
Although this vulnerability reportedly affects linux-atm 2.4.0, previous versions may also be affected.
The linux-atm 'les' executable has been reported prone to a buffer overflow vulnerability.
This issue is due to a lack of sufficient bounds checking performed on data supplied via specific command line arguments to the 'les' executable. Excessive data may overrun the bounds of an internal memory buffer and corrupt adjacent memory. As a direct result of this issue arbitrary code execution is possible.
Although this vulnerability reportedly affects linux-atm 2.4.0, previous versions may also be affected.
Exploit / POC
Linux-ATM LES Command Line Argument Buffer Overflow Vulnerability
The following proof of concept exploit has been supplied:
The following proof of concept exploit has been supplied:
Solution / Fix
Linux-ATM LES Command Line Argument Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linux-ATM LES Command Line Argument Buffer Overflow Vulnerability
References:
References:
- linux-atm Homepage (Linux-atm)
- ATM on Linux Exploit Code Release (les, local) (Angelo Rosiello
)