Stack-based buffer overflow in tmsnc CVE-2008-2828

Bug #242517 reported by Emanuele Gentili
256
Affects Status Importance Assigned to Milestone
tmsnc (Debian)
Fix Released
Unknown
tmsnc (Ubuntu)
Fix Released
Medium
Emanuele Gentili
Dapper
Won't Fix
Undecided
Unassigned
Gutsy
Fix Released
Undecided
Unassigned
Hardy
Fix Released
Undecided
Unassigned
Intrepid
Invalid
Undecided
Unassigned

Bug Description

Stack-based buffer overflow in tmsnc allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an MSN packet with a UBX commands containing a large UBX payload length field.

Revision history for this message
Emanuele Gentili (emgent) wrote :
Revision history for this message
Emanuele Gentili (emgent) wrote :
Revision history for this message
Emanuele Gentili (emgent) wrote :
Changed in tmsnc:
assignee: nobody → emgent
importance: Undecided → Medium
status: New → In Progress
Changed in tmsnc:
status: Unknown → Fix Released
Revision history for this message
Emanuele Gentili (emgent) wrote :

Intrepid fix synced.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thanks for the debdiffs! Can you post your testing for each release and architecture tested? Once that is done I can push these out.

Revision history for this message
Emanuele Gentili (emgent) wrote :

Hello

This fix is synced by Debian, tested in all ubuntu version on x86.

The POC and the test is available on http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487222.

Changed in tmsnc:
status: In Progress → Fix Released
Changed in tmsnc:
status: New → In Progress
status: New → Invalid
status: New → In Progress
status: In Progress → Fix Released
status: In Progress → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. dapper has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against dapper is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in tmsnc (Ubuntu Dapper):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.