|
From: ChrisR- <chris@cr-secure.net>
Date: Thu Aug 19 2004 - 19:28:40 EDT
Pads Stack Overflow Advisory
---[ Vulnerable Application ]---
Pads - Passive Asset Detection System
Vulnerable to a stack overflow.
---[ Vulnerable Code ]---
From pads.c
<code snip>
......
char report_file[255] = "assets.csv";
.........
case 'w':
</code snip>
Very simple stack overflow. Can be exploited locally with
_______________________________________________-
The Return Value Is: 0xbffff8b8
pads - Passive Asset Detection System
sh-3.00$ id
This is typically only a big deal if 'pads' is uid=0. Which it is not by
---[ Temporary work around ]---
Well for now you could change strcpy() to
.......
Matt Shelton (author) was notified of this, a new version 1.1.1 is now
---[ Hello ]---
Mattjf && tlharris && Think && others
www.cr-secure.net
_______________________________________________
This archive was generated by hypermail 2.1.8 : Wed Aug 18 2004 - 22:04:10 EDT |
Custom Search
|