VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 2) [ Download XML
CVE-2010-1938
freebsd, opie: Off-by-one error in the __opiereadrec function in r...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1938

Original

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-28
Source Information Category:
Advisory, Alert
Last Updated:
2010-06-01




Affected Product Tags
cpe:/a:nrl:opie:2.10
cpe:/a:nrl:opie:2.11
cpe:/a:nrl:opie:2.2
cpe:/a:nrl:opie:2.21
cpe:/a:nrl:opie:2.22
cpe:/a:nrl:opie:2.3
cpe:/a:nrl:opie:2.32
cpe:/a:nrl:opie:2.4
cpe:/a:nrl:opie:2.4.1:test1 and previous versions
cpe:/o:freebsd:freebsd:6.4
cpe:/o:freebsd:freebsd:6.4:release
cpe:/o:freebsd:freebsd:6.4:release_p2
cpe:/o:freebsd:freebsd:6.4:release_p3
cpe:/o:freebsd:freebsd:6.4:release_p4
cpe:/o:freebsd:freebsd:6.4:release_p5
cpe:/o:freebsd:freebsd:6.4:stable
cpe:/o:freebsd:freebsd:6:stable
cpe:/o:freebsd:freebsd:7.0
cpe:/o:freebsd:freebsd:7.0-release
cpe:/o:freebsd:freebsd:7.0:beta_4
cpe:/o:freebsd:freebsd:7.0:current
cpe:/o:freebsd:freebsd:7.0:pre-release
cpe:/o:freebsd:freebsd:7.0:release
cpe:/o:freebsd:freebsd:7.0:release-p12
cpe:/o:freebsd:freebsd:7.0:release-p8
cpe:/o:freebsd:freebsd:7.0:release-p9
cpe:/o:freebsd:freebsd:7.0:releng
cpe:/o:freebsd:freebsd:7.0:stable
cpe:/o:freebsd:freebsd:7.0_beta4
cpe:/o:freebsd:freebsd:7.0_releng
cpe:/o:freebsd:freebsd:7.1
cpe:/o:freebsd:freebsd:7.1:pre-release
cpe:/o:freebsd:freebsd:7.1:rc1
cpe:/o:freebsd:freebsd:7.1:release-p1
cpe:/o:freebsd:freebsd:7.1:release-p2
cpe:/o:freebsd:freebsd:7.1:release-p4
cpe:/o:freebsd:freebsd:7.1:release-p5
cpe:/o:freebsd:freebsd:7.1:release-p6
cpe:/o:freebsd:freebsd:7.1:stable
cpe:/o:freebsd:freebsd:7.2
cpe:/o:freebsd:freebsd:7.2:pre-release
cpe:/o:freebsd:freebsd:7.2:stable
cpe:/o:freebsd:freebsd:8.0
cpe:/o:freebsd:freebsd:8.1-prerelease
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
BID 40403




FREEBSD FreeBSD-SA-10:05




MISC http://site.pi3.com.pl/adv/libopie-adv.txt




MISC http://blog.pi3.com.pl/?p=111




SECTRACK 1024040




SECUNIA 39966




SECUNIA 39963




SREASON 7450




SREASONRES 20100527 libopie __readrec() off-by one (FreeBSD ftpd remote PoC)




Vulnerability Type Numeric Errors (CWE-189)





Copyright © 2010 JPCERT/CC All Rights Reserved.