Netstd 3.07-17 multiple remote buffer overflows

From: Spybreak (spybreakat_private)
Date: Fri May 24 2002 - 01:39:23 PDT

  • Next message: securityat_private: "Security Update: [CSSA-2002-SCO.20] OpenServer 5.0.5 OpenServer 5.0.6 : popper buffer overflow and denial-of-service"

    Release  : May 24, 2002
    Author   : Spybreak (spybreakat_private)
    Software : netstd
    Version  : 3.07-17
    URL      : debian.org
    Status   : vendor contacted
    Problem  : Multiple remote buffer overflows
    
    
    
    --- Intro ---
    
    Netstd is a package of networking utilities and daemons
    from the Debian Linux distribution.
    
    --- Problem ---
    
    It is possible to remotely overflow buffers in several utilities
    from the package, through owned DNS server.
    The FQDN obtained from the reply is simply copied into small fixed
    size buffer, without any check on the length of the answer.
    
    The same problem is present in these utils from the netstd 3.07-17
    package:
    
    - linux-ftpd
    - pcnfsd
    - tftp
    - traceroute
    - from/to
    
    
    
    Public key:
    http://spybreak.host.sk
    



    This archive was generated by hypermail 2b30 : Fri May 24 2002 - 05:57:36 PDT