OSVDB ID: 3329

Title: nd Overflow

Info

Disclosure

Nov 29, 2003

Discovery

Nov 29, 2003

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in nd. The vendor announced the vulnerability and did not release details. With a specially crafted request, a malicious web server operator can cause arbitrary code to execute resulting in a loss of confidentiality, integrity, and/or availability.

Classification

Attack Type: Input Manipulation

Solution

Upgrade to version 0.8.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Yuuichi Teranishi

nd

0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218