Network Security News – Tuesday, November 15, 2005 Events
Heimdal Kerberos kf / kfd Multiple Buffer Overflows
Multiple remote overflows exist in Heimdal Kerberos. The 'kf' binary and the 'kfd' daemon fail to perform proper bounds checking resulting in multiple buffer overflows. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.. Read more at osvdb.org/5618
iCMS index.php page Variable Remote File Inclusion
iCMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'index.php' not properly sanitizing user input supplied to the 'page' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.. Read more at osvdb.org/20820
NetBSD libz Zero Length Code Incorrect Error DoS
NetBSD contains a flaw that may allow a remote denial of service. The issue is triggered when huft_build() of the zlib routines permits a malicious attacker to use a specially crafted, compressed file to cause a NULL deference, resulting in loss of availability for the platform.. Read more at osvdb.org/20728
NetBSD telnetd Static Local Variable Overflow
NetBSD contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when telnetd utilizes static variables, allowing a malicious user to cause a buffer overflow and change the flow of execution. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20726
Leave a Reply