Bugtraq mailing list archives
Netstd 3.07-17 multiple remote buffer overflows
From: Spybreak <spybreak () host sk>
Date: Fri, 24 May 2002 10:39:23 +0200 (CEST)
Release : May 24, 2002 Author : Spybreak (spybreak () host sk) Software : netstd Version : 3.07-17 URL : debian.org Status : vendor contacted Problem : Multiple remote buffer overflows --- Intro --- Netstd is a package of networking utilities and daemons from the Debian Linux distribution. --- Problem --- It is possible to remotely overflow buffers in several utilities from the package, through owned DNS server. The FQDN obtained from the reply is simply copied into small fixed size buffer, without any check on the length of the answer. The same problem is present in these utils from the netstd 3.07-17 package: - linux-ftpd - pcnfsd - tftp - traceroute - from/to Public key: http://spybreak.host.sk
Current thread:
- Netstd 3.07-17 multiple remote buffer overflows Spybreak (May 24)
- Re: Netstd 3.07-17 multiple remote buffer overflows Lupe Christoph (May 25)