PLD Software Ebola Buffer Overflow Vulnerability
BID:9156
Info
PLD Software Ebola Buffer Overflow Vulnerability
| Bugtraq ID: | 9156 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2003 12:00AM |
| Updated: | Dec 05 2003 12:00AM |
| Credit: | Discovered by Secure Network Operations, Inc. |
| Vulnerable: |
Paul L Daniels Ebola 0.1.4 |
| Not Vulnerable: |
Paul L Daniels Ebola 0.1.5 |
Discussion
PLD Software Ebola Buffer Overflow Vulnerability
It has been reported that a buffer overflow condition is present in the authentication mechanism implemented in Ebola. The condition is due to the use of the C library function sprintf() to construct an error message when authentication is not successful. According to the discoverer of this flaw, the vulnerability is remotely exploitable.
It has been reported that a buffer overflow condition is present in the authentication mechanism implemented in Ebola. The condition is due to the use of the C library function sprintf() to construct an error message when authentication is not successful. According to the discoverer of this flaw, the vulnerability is remotely exploitable.
Exploit / POC
PLD Software Ebola Buffer Overflow Vulnerability
The discoverer of this issue has stated that exploit code has been developed. An exploit has been made available by c0wboy and is available below.
The discoverer of this issue has stated that exploit code has been developed. An exploit has been made available by c0wboy and is available below.
Solution / Fix
PLD Software Ebola Buffer Overflow Vulnerability
Solution:
The vendor has issued an upgrade, version 0.1.5, that is no longer vulnerable:
Paul L Daniels Ebola 0.1.4
Solution:
The vendor has issued an upgrade, version 0.1.5, that is no longer vulnerable:
Paul L Daniels Ebola 0.1.4
-
Paul L Daniels ebola-0.1.5.tar.gz
http://pldaniels.com/ebola/ebola-0.1.5.tar.gz
References
PLD Software Ebola Buffer Overflow Vulnerability
References:
References:
- ebola 0.1.4 remote exploit (c0wboy@0x333
) - SRT2003-12-04-0723 - PLDaniels Ebola remote overflow (KF
)