Debian hztty Multiple Buffer Overflow Vulnerabilities
BID:8656
Info
Debian hztty Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 8656 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0783 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 19 2003 12:00AM |
| Updated: | Sep 05 2006 10:13PM |
| Credit: | The disclosure of these issue have been credited to Jens Steube. |
| Vulnerable: |
Debian hztty 2.0 -5.2 |
| Not Vulnerable: | |
Discussion
Debian hztty Multiple Buffer Overflow Vulnerabilities
Multiple buffer-overflow vulnerabilities occur in Debian's hztty program. These issues may allow an attacker to gain unauthorized access to a vulnerable host. The issues occur because the utility fails to do sufficient boundary checking.
Successful exploitation of these issue may allow an attacker to execute arbitrary code in the context of the user who is running the vulnerable software.
Version 2.0-5.2 of hztty has been reported vulnerable; other versions may be affected as well.
Multiple buffer-overflow vulnerabilities occur in Debian's hztty program. These issues may allow an attacker to gain unauthorized access to a vulnerable host. The issues occur because the utility fails to do sufficient boundary checking.
Successful exploitation of these issue may allow an attacker to execute arbitrary code in the context of the user who is running the vulnerable software.
Version 2.0-5.2 of hztty has been reported vulnerable; other versions may be affected as well.
Exploit / POC
Debian hztty Multiple Buffer Overflow Vulnerabilities
The following exploit has been released:
The following exploit has been released:
Solution / Fix
Debian hztty Multiple Buffer Overflow Vulnerabilities
Solution:
Debian has released an advisory (DSA 385-1) and fixes to address this issue. Please see the referenced advisory for details.
Debian hztty 2.0 -5.2
Solution:
Debian has released an advisory (DSA 385-1) and fixes to address this issue. Please see the referenced advisory for details.
Debian hztty 2.0 -5.2
-
Debian hztty_2.0-5.2woody1_alpha.deb
Upgrade for Alpha architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_alpha.deb -
Debian hztty_2.0-5.2woody1_arm.deb
Upgrade for ARM architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_arm.deb -
Debian hztty_2.0-5.2woody1_hppa.deb
Upgrade for HP Precision architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_hppa.deb -
Debian hztty_2.0-5.2woody1_i386.deb
Upgrade for Intel IA-32 architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_i386.deb -
Debian hztty_2.0-5.2woody1_ia64.deb
Upgrade for Intel IA-64 architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_ia64.deb -
Debian hztty_2.0-5.2woody1_m68k.deb
Upgrade for Motorola 680x0 architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_m68k.deb -
Debian hztty_2.0-5.2woody1_mips.deb
Upgrade for Big endian MIPS architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_mips.deb -
Debian hztty_2.0-5.2woody1_mipsel.deb
Upgrade for Little endian MIPS architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_mipsel.deb -
Debian hztty_2.0-5.2woody1_powerpc.deb
Upgrade for PowerPC architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_powerpc.deb -
Debian hztty_2.0-5.2woody1_s390.deb
Upgrade for IBM S/390 architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_s390.deb -
Debian hztty_2.0-5.2woody1_sparc.deb
Upgrade for Sun Sparc architecture.
http://security.debian.org/pool/updates/main/h/hztty/hztty_2.0-5.2wood y1_sparc.deb