[25550] in bugtraq

home help back first fref pref prev next nref lref last post

Netstd 3.07-17 multiple remote buffer overflows

daemon@ATHENA.MIT.EDU (Spybreak)
Fri May 24 09:24:00 2002

Date: Fri, 24 May 2002 10:39:23 +0200 (CEST)
From: Spybreak <spybreak@host.sk>
To: <bugtraq@securityfocus.com>
Message-ID: <Pine.LNX.4.33L2.0205241031120.10734-100000@creon.profinet.sk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII



Release  : May 24, 2002
Author   : Spybreak (spybreak@host.sk)
Software : netstd
Version  : 3.07-17
URL      : debian.org
Status   : vendor contacted
Problem  : Multiple remote buffer overflows



--- Intro ---

Netstd is a package of networking utilities and daemons
from the Debian Linux distribution.

--- Problem ---

It is possible to remotely overflow buffers in several utilities
from the package, through owned DNS server.
The FQDN obtained from the reply is simply copied into small fixed
size buffer, without any check on the length of the answer.

The same problem is present in these utils from the netstd 3.07-17
package:

- linux-ftpd
- pcnfsd
- tftp
- traceroute
- from/to



Public key:
http://spybreak.host.sk



home help back first fref pref prev next nref lref last post