OSVDB ID: 11179

Title: libxml2 FTP URL Processing Overflow

Info

Disclosure

Oct 25, 2004

Discovery

Unknown

Dates

Exploit

Oct 25, 2004

Solution

Unknown

Description

A remote overflow exists in libxml2. libxml2's nanoftp.c xmlNanoFTPScanURL() function fails to perform boundary checking of user-supplied data that is copied into a finite stack buffer, which could potentially cause a stack-based overflow. Using a specially crafted URL, an attacker can cause a denial of service or execute arbitrary code resulting in a loss of integrity or availability.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity, Loss of Availability
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Upgrade to version 2.6.15 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Daniel Veillard

Libxml2

2.6.14
2.6.13
2.6.12
2.6.11
2.6.10
2.6.9
2.6.8
2.6.7
2.6.6

References

Credit

  • infamous41md - infamous41mdBrand New Doo Doohotpop.com -


Direct URL: http://osvdb.org/36218