Typespeed Remote Memory Corruption Vulnerability
BID:7891
Info
Typespeed Remote Memory Corruption Vulnerability
| Bugtraq ID: | 7891 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0435 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Typespeed Typespeed 0.4.1 Typespeed Typespeed 0.4 |
| Not Vulnerable: | |
Discussion
Typespeed Remote Memory Corruption Vulnerability
A memory corruption vulnerability has been reported for Typespeed that may result in code execution with elevated privileges. The vulnerability exists in the net_swapscore() function where proper bounds checks are not performed prior to executing the 'strncpy' function.
A remote attacker may be able to exploit this vulnerability to corrupt sensitive with attacker-supplied code.
A memory corruption vulnerability has been reported for Typespeed that may result in code execution with elevated privileges. The vulnerability exists in the net_swapscore() function where proper bounds checks are not performed prior to executing the 'strncpy' function.
A remote attacker may be able to exploit this vulnerability to corrupt sensitive with attacker-supplied code.
Exploit / POC
Typespeed Remote Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Typespeed Remote Memory Corruption Vulnerability
Solution:
Debian has released an advisory (DSA 322-1). Information about applying fixes is available in the referenced advisory. Fixes are available below.
Typespeed Typespeed 0.4
Typespeed Typespeed 0.4.1
Solution:
Debian has released an advisory (DSA 322-1). Information about applying fixes is available in the referenced advisory. Fixes are available below.
Typespeed Typespeed 0.4
-
Debian typespeed_0.4.0-5.2_alpha.deb
Alpha
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .0-5.2_alpha.deb -
Debian typespeed_0.4.0-5.2_arm.deb
ARM
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .0-5.2_arm.deb -
Debian typespeed_0.4.0-5.2_i386.deb
IA-32
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .0-5.2_i386.deb -
Debian typespeed_0.4.0-5.2_m68k.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .0-5.2_m68k.deb -
Debian typespeed_0.4.0-5.2_powerpc.deb
PowerPC
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .0-5.2_powerpc.deb -
Debian typespeed_0.4.0-5.2_sparc.deb
Sparc
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .0-5.2_sparc.deb
Typespeed Typespeed 0.4.1
-
Debian typespeed_0.4.1-2.2_alpha.deb
Alpha
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_alpha.deb -
Debian typespeed_0.4.1-2.2_arm.deb
ARM
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_arm.deb -
Debian typespeed_0.4.1-2.2_hppa.deb
HP
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_hppa.deb -
Debian typespeed_0.4.1-2.2_i386.deb
IA-32
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_i386.deb -
Debian typespeed_0.4.1-2.2_ia64.deb
IA-64
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_ia64.deb -
Debian typespeed_0.4.1-2.2_m68k.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_m68k.deb -
Debian typespeed_0.4.1-2.2_mips.deb
Big endian MIPS
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_mips.deb -
Debian typespeed_0.4.1-2.2_mipsel.deb
Little endian MIPS
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_mipsel.deb -
Debian typespeed_0.4.1-2.2_powerpc.deb
PowerPC
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_powerpc.deb -
Debian typespeed_0.4.1-2.2_s390.deb
IBM S/390
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_s390.deb -
Debian typespeed_0.4.1-2.2_sparc.deb
Sun Sparc
http://security.debian.org/pool/updates/main/t/typespeed/typespeed_0.4 .1-2.2_sparc.deb
References
Typespeed Remote Memory Corruption Vulnerability
References:
References: