GNU Indent Local Heap Overflow Vulnerability
BID:9297
Info
GNU Indent Local Heap Overflow Vulnerability
| Bugtraq ID: | 9297 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 26 2003 12:00AM |
| Updated: | Dec 26 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Winnie The Pooh Hacking Squadron. |
| Vulnerable: |
GNU Indent 2.2.9 |
| Not Vulnerable: | |
Discussion
GNU Indent Local Heap Overflow Vulnerability
It has been reported that GNU Indent may be prone to a local heap overflow vulnerability that can be exploited through a malicious C source input file. It has been reported that indent copies data from the file to a 1000 byte long buffer without sufficient boundary checking. A heap overflow condition can be triggered, which may result in memory being overwritten and, ultimately, malicious code execution with the privileges of the user running indent.
GNU Indent version 2.2.9 has been reported to be prone this issue, however, other versions may be affected as well.
It has been reported that GNU Indent may be prone to a local heap overflow vulnerability that can be exploited through a malicious C source input file. It has been reported that indent copies data from the file to a 1000 byte long buffer without sufficient boundary checking. A heap overflow condition can be triggered, which may result in memory being overwritten and, ultimately, malicious code execution with the privileges of the user running indent.
GNU Indent version 2.2.9 has been reported to be prone this issue, however, other versions may be affected as well.
Exploit / POC
GNU Indent Local Heap Overflow Vulnerability
Exploit code for indent 2.2.9 for slackware 9.0 has been provided:
Exploit code for indent 2.2.9 for slackware 9.0 has been provided:
Solution / Fix
GNU Indent Local Heap Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.