SLRN XRef Buffer Overflow Vulnerabilty
BID:8493
Info
SLRN XRef Buffer Overflow Vulnerabilty
| Bugtraq ID: | 8493 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2003 12:00AM |
| Updated: | Aug 26 2003 12:00AM |
| Credit: | This vulnerability has been announced by the vendor. |
| Vulnerable: |
SLRN Development Team slrn 0.9.7 .4 SLRN Development Team slrn 0.9.7 .3 SLRN Development Team slrn 0.9.7 .2 SLRN Development Team slrn 0.9.7 .1 SLRN Development Team slrn 0.9.7 .0a SLRN Development Team slrn 0.9.7 .0 SLRN Development Team slrn 0.9.6 .4 SLRN Development Team slrn 0.9.6 .3 SLRN Development Team slrn 0.9.6 .2-9 SLRN Development Team slrn 0.9.6 .2 |
| Not Vulnerable: |
SLRN Development Team slrn 0.9.8 |
Discussion
SLRN XRef Buffer Overflow Vulnerabilty
slrn has been reported prone to a remote buffer overflow condition.
The issue has been reported to present itself when handling malicious Xref headers. Although unconfirmed, due to the nature of this vulnerability it has been conjectured that a remote attacker may exploit this issue to influence the execution flow of the affected slrn application. This could result in arbitrary code execution in the context of the user running slrn.
slrn has been reported prone to a remote buffer overflow condition.
The issue has been reported to present itself when handling malicious Xref headers. Although unconfirmed, due to the nature of this vulnerability it has been conjectured that a remote attacker may exploit this issue to influence the execution flow of the affected slrn application. This could result in arbitrary code execution in the context of the user running slrn.
Exploit / POC
SLRN XRef Buffer Overflow Vulnerabilty
Although unconfirmed, exploits for this vulnerability have been reported to be public.
Although unconfirmed, exploits for this vulnerability have been reported to be public.
Solution / Fix
SLRN XRef Buffer Overflow Vulnerabilty
Solution:
The vendor has released an update to address this issue:
SLRN Development Team slrn 0.9.6 .4
SLRN Development Team slrn 0.9.6 .3
SLRN Development Team slrn 0.9.6 .2-9
SLRN Development Team slrn 0.9.6 .2
SLRN Development Team slrn 0.9.7 .1
SLRN Development Team slrn 0.9.7 .4
SLRN Development Team slrn 0.9.7 .2
SLRN Development Team slrn 0.9.7 .0
SLRN Development Team slrn 0.9.7 .0a
SLRN Development Team slrn 0.9.7 .3
Solution:
The vendor has released an update to address this issue:
SLRN Development Team slrn 0.9.6 .4
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.6 .3
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.6 .2-9
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.6 .2
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.7 .1
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.7 .4
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.7 .2
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.7 .0
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.7 .0a
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768
SLRN Development Team slrn 0.9.7 .3
-
SLRN Development Team slrn-0.9.8.0.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=7768