Dizzy unix2tcp Unspecified Buffer Overflow Vulnerability
BID:9240
Info
Dizzy unix2tcp Unspecified Buffer Overflow Vulnerability
| Bugtraq ID: | 9240 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 17 2003 12:00AM |
| Updated: | Dec 17 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to David Hill and the FINK project. |
| Vulnerable: |
Dizzy unix2tcp 0.7.2 Dizzy unix2tcp 0.7.1 Dizzy unix2tcp 0.7 |
| Not Vulnerable: |
Dizzy unix2tcp 0.8 |
Discussion
Dizzy unix2tcp Unspecified Buffer Overflow Vulnerability
It has been reported that unix2tcp may be prone to a buffer overflow condition, which may allow an attacker to gain unauthorized access to a vulnerable system. The issue is caused due to insufficient boundary checking in the 'unix2tcp.c' module.
unix2tcp versions 0.7.2 and prior may be vulnerable to this issue. This BID will be updated as more information becomes available.
It has been reported that unix2tcp may be prone to a buffer overflow condition, which may allow an attacker to gain unauthorized access to a vulnerable system. The issue is caused due to insufficient boundary checking in the 'unix2tcp.c' module.
unix2tcp versions 0.7.2 and prior may be vulnerable to this issue. This BID will be updated as more information becomes available.
Exploit / POC
Dizzy unix2tcp Unspecified Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Dizzy unix2tcp Unspecified Buffer Overflow Vulnerability
Solution:
The vendor has released unix2tcp 0.8.0 which is not vulnerable to this issue.
Dizzy unix2tcp 0.7
Dizzy unix2tcp 0.7.1
Dizzy unix2tcp 0.7.2
Solution:
The vendor has released unix2tcp 0.8.0 which is not vulnerable to this issue.
Dizzy unix2tcp 0.7
-
Dizzy unix2tcp-0.8.0.tar.gz
http://dizzy.roedu.net/unix2tcp/unix2tcp-0.8.0.tar.gz
Dizzy unix2tcp 0.7.1
-
Dizzy unix2tcp-0.8.0.tar.gz
http://dizzy.roedu.net/unix2tcp/unix2tcp-0.8.0.tar.gz
Dizzy unix2tcp 0.7.2
-
Dizzy unix2tcp-0.8.0.tar.gz
http://dizzy.roedu.net/unix2tcp/unix2tcp-0.8.0.tar.gz