GNU Queue Remote Buffer Overflows May Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1012929
|
|
SecurityTracker URL: http://securitytracker.com/id?1012929
|
|
CVE Reference: CAN-2004-0555
(Links to External Site)
|
Date: Jan 18 2005
|
Impact: Execution of arbitrary code via network, User access via network
|
Version(s): 1.30.1
|
Description: Some buffer overflow vulnerabilities were reported in queue. A remote user may be able to execute arbitrary code.
Debian reported several buffer overflow vulnerabilities in queue that can be triggered by a remote user.
The flaws reside in 'queue.c'
and 'queued.c'.
"jaguar" of the Debian Security Audit Project is credited with discovering these flaws.
|
Impact: A remote user may be able to execute arbitrary code on the target system [however, code execution was not confirmed in the report].
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.gnu.org/software/queue/queue.html (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 18 Jan 2005 05:19:19 -0500
Subject: [none]
|
Debian reported several buffer overflow vulnerabilities in queue.
"jaguar" of the Debian Security Audit Project is credited with discovering these flaws.
CVE: CAN-2004-0555
|
|