Poptop PPTP BCRELAY fscanf() Buffer Overflow Vulnerability
BID:7590
Info
Poptop PPTP BCRELAY fscanf() Buffer Overflow Vulnerability
| Bugtraq ID: | 7590 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2003 12:00AM |
| Updated: | May 14 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Hernan Otero <[email protected]>. |
| Vulnerable: |
PoPToP PPTP Server 1.1.4 -b3 PoPToP PPTP Server 1.1.4 -b2 PoPToP PPTP Server 1.1.4 -b1 |
| Not Vulnerable: |
PoPToP PPTP Server 1.1.4 -b4 |
Discussion
Poptop PPTP BCRELAY fscanf() Buffer Overflow Vulnerability
A vulnerability has been discovered in Poptop pptpd-1.1.4 b3 and earlier. The problem occurs due to insufficient bounds checking before calling the fscanf() function. As a result, it may be possible for a malicious attacker to supply excessive data to the program which may trigger memory corruption. This data will be read from a file being accessed by Poptop. As a result, an attacker must have sufficient privileges to construct a file which will be read by Poptop.
Successful exploitation of this issue may allow an attacker to execution arbitrary commands with the privileges of Poptop, typically root.
A vulnerability has been discovered in Poptop pptpd-1.1.4 b3 and earlier. The problem occurs due to insufficient bounds checking before calling the fscanf() function. As a result, it may be possible for a malicious attacker to supply excessive data to the program which may trigger memory corruption. This data will be read from a file being accessed by Poptop. As a result, an attacker must have sufficient privileges to construct a file which will be read by Poptop.
Successful exploitation of this issue may allow an attacker to execution arbitrary commands with the privileges of Poptop, typically root.
Exploit / POC
Poptop PPTP BCRELAY fscanf() Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Poptop PPTP BCRELAY fscanf() Buffer Overflow Vulnerability
Solution:
An upgraded version of PoPToP PPTP has been released to address this issue.
PoPToP PPTP Server 1.1.4 -b3
PoPToP PPTP Server 1.1.4 -b1
PoPToP PPTP Server 1.1.4 -b2
Solution:
An upgraded version of PoPToP PPTP has been released to address this issue.
PoPToP PPTP Server 1.1.4 -b3
-
PoPToP pptpd-1.1.4-b4.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=44827
PoPToP PPTP Server 1.1.4 -b1
-
PoPToP pptpd-1.1.4-b4.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=44827
PoPToP PPTP Server 1.1.4 -b2
-
PoPToP pptpd-1.1.4-b4.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=44827
References
Poptop PPTP BCRELAY fscanf() Buffer Overflow Vulnerability
References:
References:
- PoPToP PPTP Homepage (PoPToP)