ISC INN Control Message Handling Buffer Overrun Vulnerability
BID:9382
Info
ISC INN Control Message Handling Buffer Overrun Vulnerability
| Bugtraq ID: | 9382 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0045 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2004 12:00AM |
| Updated: | Mar 19 2015 09:16AM |
| Credit: | Discovery is credited to Dan Riley. |
| Vulnerable: |
ISC INN 2.4 .0 |
| Not Vulnerable: |
ISC INN 2.4.1 |
Discussion
ISC INN Control Message Handling Buffer Overrun Vulnerability
ISC has reported a remotely exploitable buffer overrun in INN. This issue exists in the control message handling code that was introduced into version 2.4.0. It may possible to exploit this issue to execute arbitrary code in the context of the innd process. It should be noted that innd is designed to drop privileges after binding to port 119, so successful exploitation would typically only yield the privileges of the news user.
ISC has reported a remotely exploitable buffer overrun in INN. This issue exists in the control message handling code that was introduced into version 2.4.0. It may possible to exploit this issue to execute arbitrary code in the context of the innd process. It should be noted that innd is designed to drop privileges after binding to port 119, so successful exploitation would typically only yield the privileges of the news user.
Exploit / POC
ISC INN Control Message Handling Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ISC INN Control Message Handling Buffer Overrun Vulnerability
Solution:
OpenPKG has released an advisory (OpenPKG-SA-2004.001) to address this issue. inn-2.4.0-20040108 for OpenPKG CURRENT includes fixes as does inn-2.4.0-1.3.1 for OpenPKG 1.3. Please see the attached advisory for further details.
Slackware has released an advisory and fixes to address this issue.
This issue has been addressed in ISC INN 2.4.1.
ISC INN 2.4 .0
Solution:
OpenPKG has released an advisory (OpenPKG-SA-2004.001) to address this issue. inn-2.4.0-20040108 for OpenPKG CURRENT includes fixes as does inn-2.4.0-1.3.1 for OpenPKG 1.3. Please see the attached advisory for further details.
Slackware has released an advisory and fixes to address this issue.
This issue has been addressed in ISC INN 2.4.1.
ISC INN 2.4 .0
-
ISC inn-2.4.1.tar.gz
ftp://ftp.isc.org/isc/inn/inn-2.4.1.tar.gz -
OpenPKG inn-2.4.0-1.3.1.src.rpm
ftp://ftp.openpkg.org/release/1.3/UPD/inn-2.4.0-1.3.1.src.rpm -
Slackware inn-2.4.1-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/i nn-2.4.1-i386-1.tgz -
Slackware inn-2.4.1-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/i nn-2.4.1-i486-1.tgz -
Slackware inn-2.4.1-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/extra/inn/inn- 2.4.1-i486-1.tgz
References
ISC INN Control Message Handling Buffer Overrun Vulnerability
References:
References:
- INN Homepage (ISC)
- [SECURITY] INN: Buffer overflow in control message handling (Russ Allbery
)