Pine rfc2231_get_param() Remote Integer Overflow Vulnerability
BID:8589
Info
Pine rfc2231_get_param() Remote Integer Overflow Vulnerability
| Bugtraq ID: | 8589 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0721 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery credited to zen-parse. |
| Vulnerable: |
University of Washington Pine 4.56 University of Washington Pine 4.53 University of Washington Pine 4.52 University of Washington Pine 4.50 University of Washington Pine 4.44 University of Washington Pine 4.33 University of Washington Pine 4.30 University of Washington Pine 4.21 University of Washington Pine 4.20 University of Washington Pine 4.10 University of Washington Pine 4.0.4 University of Washington Pine 4.0.2 University of Washington Pine 3.98 SGI ProPack 2.3 SGI ProPack 2.2.1 |
| Not Vulnerable: | |
Discussion
Pine rfc2231_get_param() Remote Integer Overflow Vulnerability
A vulnerability has been reported to be present in the software that may allow a remote attacker to cause an integer overflow condition in order to execute arbitrary code on a vulnerable system. The problem is reported to exist in the rfc2231_get_param() function found in the strings.c file.
Successful exploitation of this issue may allow a remote attacker to execute arbitrary code on a remote system in order to gain unautorized access.
A vulnerability has been reported to be present in the software that may allow a remote attacker to cause an integer overflow condition in order to execute arbitrary code on a vulnerable system. The problem is reported to exist in the rfc2231_get_param() function found in the strings.c file.
Successful exploitation of this issue may allow a remote attacker to execute arbitrary code on a remote system in order to gain unautorized access.
Exploit / POC
Pine rfc2231_get_param() Remote Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Pine rfc2231_get_param() Remote Integer Overflow Vulnerability
References:
References:
- CLSA-2003:738 (Conectiva)
- RHSA-2003-274 (Red Hat)
- Sun Linux Support - Sun Linux Patches (Sun)
- iDEFENSE Security Advisory 09.10.03: Two Exploitable Overflows in PINE ("iDEFENSE Labs"
)