nd Multiple Buffer Overrun Vulnerabilities
BID:9365
Info
nd Multiple Buffer Overrun Vulnerabilities
| Bugtraq ID: | 9365 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0014 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2004 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery is credited to Fumitoshi UKAI. |
| Vulnerable: |
nd nd 0.5 .0 |
| Not Vulnerable: | |
Discussion
nd Multiple Buffer Overrun Vulnerabilities
Multiple buffer overrun vulnerabilities were reported in nd. The source of the vulnerabilities appears to be multiple instances where sprintf() operations are performed on server-supplied data without proper bounds checking.
These issues may be exploited by a malicious WebDAV server to execute arbitrary code in the context of the software.
Multiple buffer overrun vulnerabilities were reported in nd. The source of the vulnerabilities appears to be multiple instances where sprintf() operations are performed on server-supplied data without proper bounds checking.
These issues may be exploited by a malicious WebDAV server to execute arbitrary code in the context of the software.
Exploit / POC
nd Multiple Buffer Overrun Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
nd Multiple Buffer Overrun Vulnerabilities
Solution:
Debian has released an advisory (DSA 412-1) to address these issues. Please see the attached advisory for details on obtaining and applying fixes.
nd nd 0.5 .0
Solution:
Debian has released an advisory (DSA 412-1) to address these issues. Please see the attached advisory for details on obtaining and applying fixes.
nd nd 0.5 .0
-
Debian nd_0.5.0-1woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_alp ha.deb -
Debian nd_0.5.0-1woody1_arm.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_arm .deb -
Debian nd_0.5.0-1woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_hpp a.deb -
Debian nd_0.5.0-1woody1_i386.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_i38 6.deb -
Debian nd_0.5.0-1woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_ia6 4.deb -
Debian nd_0.5.0-1woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_m68 k.deb -
Debian nd_0.5.0-1woody1_mips.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_mip s.deb -
Debian nd_0.5.0-1woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_mip sel.deb -
Debian nd_0.5.0-1woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_pow erpc.deb -
Debian nd_0.5.0-1woody1_s390.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_s39 0.deb -
Debian nd_0.5.0-1woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/nd/nd_0.5.0-1woody1_spa rc.deb
References
nd Multiple Buffer Overrun Vulnerabilities
References:
References: