8493300 2002-05-24 10:39 +0200 /44 rader/ Spybreak <spybreak@host.sk> Sänt av: joel@lysator.liu.se Importerad: 2002-05-24 15:17 av Brevbäraren Extern mottagare: bugtraq@securityfocus.com Mottagare: Bugtraq (import) <22382> Ärende: Netstd 3.07-17 multiple remote buffer overflows ------------------------------------------------------------ From: Spybreak <spybreak@host.sk> To: <bugtraq@securityfocus.com> Message-ID: <Pine.LNX.4.33L2.0205241031120.10734-100000@creon.profinet.sk> Release : May 24, 2002 Author : Spybreak (spybreak@host.sk) Software : netstd Version : 3.07-17 URL : debian.org Status : vendor contacted Problem : Multiple remote buffer overflows --- Intro --- Netstd is a package of networking utilities and daemons from the Debian Linux distribution. --- Problem --- It is possible to remotely overflow buffers in several utilities from the package, through owned DNS server. The FQDN obtained from the reply is simply copied into small fixed size buffer, without any check on the length of the answer. The same problem is present in these utils from the netstd 3.07-17 package: - linux-ftpd - pcnfsd - tftp - traceroute - from/to Public key: http://spybreak.host.sk (8493300) /Spybreak <spybreak@host.sk>/-------------