ISDNRep Command Line Argument Local Buffer Overflow Vulnerability
BID:8100
Info
ISDNRep Command Line Argument Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8100 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 03 2003 12:00AM |
| Updated: | Jul 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to t0asty [ [email protected] ]. |
| Vulnerable: |
isdnrep isdnrep 4.56 |
| Not Vulnerable: | |
Discussion
ISDNRep Command Line Argument Local Buffer Overflow Vulnerability
isdnrep has been reported prone to a local command line argument buffer overflow vulnerability.
The issue presents itself due do a lack of sufficient bounds checking performed on user-supplied data that is copied from the command line into a reserved internal memory buffer. It is possible for a local attacker to influence the execution flow of isdnrep and have arbitrary operation codes executed in the context of the vulnerable application. Exploitation could permit privilege escalation on systems where the application is installed setuid/setgid.
It should be noted that although isdnrep version 4.56 has been reported vulnerable, other versions might also be vulnerable.
isdnrep has been reported prone to a local command line argument buffer overflow vulnerability.
The issue presents itself due do a lack of sufficient bounds checking performed on user-supplied data that is copied from the command line into a reserved internal memory buffer. It is possible for a local attacker to influence the execution flow of isdnrep and have arbitrary operation codes executed in the context of the vulnerable application. Exploitation could permit privilege escalation on systems where the application is installed setuid/setgid.
It should be noted that although isdnrep version 4.56 has been reported vulnerable, other versions might also be vulnerable.
Exploit / POC
ISDNRep Command Line Argument Local Buffer Overflow Vulnerability
The following proof of concept exploits have been supplied:
The following proof of concept exploits have been supplied:
Solution / Fix
ISDNRep Command Line Argument Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ISDNRep Command Line Argument Local Buffer Overflow Vulnerability
References:
References: