Citadel/UX Configuration Buffer Overrun Vulnerability
BID:8191
Info
Citadel/UX Configuration Buffer Overrun Vulnerability
| Bugtraq ID: | 8191 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2003 12:00AM |
| Updated: | Jul 15 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Carl Livitt <[email protected]> and br00t <[email protected]>. |
| Vulnerable: |
Citadel/UX Citadel/UX 6.0 7 Citadel/UX Citadel/UX 5.90 |
| Not Vulnerable: |
Citadel/UX Citadel/UX 6.0 8 |
Discussion
Citadel/UX Configuration Buffer Overrun Vulnerability
Citadel/UX is prone to a buffer overrun when importing configuration data supplied by IPGM authenticated users. This may be exploited to execute arbitrary code in the context of the server.
Citadel/UX is prone to a buffer overrun when importing configuration data supplied by IPGM authenticated users. This may be exploited to execute arbitrary code in the context of the server.
Exploit / POC
Citadel/UX Configuration Buffer Overrun Vulnerability
The following exploit leverages the issue described in BID 8193 to brute-force the IPGM password and then attempts to exploit the overrun:
The following exploit leverages the issue described in BID 8193 to brute-force the IPGM password and then attempts to exploit the overrun:
Solution / Fix
Citadel/UX Configuration Buffer Overrun Vulnerability
Solution:
The vendor has addressed this issue in Citadel/UX 6.08.
Citadel/UX Citadel/UX 5.90
Citadel/UX Citadel/UX 6.0 7
Solution:
The vendor has addressed this issue in Citadel/UX 6.08.
Citadel/UX Citadel/UX 5.90
-
Citadel/UX Citadel/UX 6.08
http://www.citadel.org/download.php
Citadel/UX Citadel/UX 6.0 7
-
Citadel/UX Citadel/UX 6.08
http://www.citadel.org/download.php