Whois Client Command Line Buffer Overrun Vulnerability
BID:8483
Info
Whois Client Command Line Buffer Overrun Vulnerability
| Bugtraq ID: | 8483 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2003 12:00AM |
| Updated: | Aug 22 2003 12:00AM |
| Credit: | Discovery is credited to Astharot. |
| Vulnerable: |
Whois Whois 4.6.6 Whois Whois 4.5.7 |
| Not Vulnerable: | |
Discussion
Whois Client Command Line Buffer Overrun Vulnerability
Whois client is prone to a buffer overrun vulnerability when handling command line parameters of excessive length. While the client is not setuid/setgid, it is often invoked in external scripts. This could present a security vulnerability if the program is invoked with untrusted input, such as via a CGI script.
It should be noted that the affected function never returns after execution. This may hinder an attacker's ability to exploit this issue to execute arbitrary code.
Whois client is prone to a buffer overrun vulnerability when handling command line parameters of excessive length. While the client is not setuid/setgid, it is often invoked in external scripts. This could present a security vulnerability if the program is invoked with untrusted input, such as via a CGI script.
It should be noted that the affected function never returns after execution. This may hinder an attacker's ability to exploit this issue to execute arbitrary code.
Exploit / POC
Whois Client Command Line Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Whois Client Command Line Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Whois Client Command Line Buffer Overrun Vulnerability
References:
References: