buffer overflow in tftp
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
netkit-tftp (Ubuntu) |
Fix Released
|
Medium
|
Kees Cook | ||
Natty |
Fix Released
|
Medium
|
Kees Cook | ||
tftp-hpa (Ubuntu) |
Fix Released
|
Medium
|
Kees Cook | ||
Natty |
Fix Released
|
Medium
|
Kees Cook |
Bug Description
Binary package hint: tftp-hpa
I'm getting a buffer overflow from tftp in both tftp-hpa and tfp packages in Natty. I'll attach each below.
Looks like something exposed by Natty's updated toolchain, as I'm not seeing this error in Maverick or Lucid.
---
Architecture: amd64
DistroRelease: Ubuntu 11.04
EcryptfsInUse: Yes
InstallationMedia: Ubuntu 11.04 "Natty Narwhal" - Alpha amd64 (20101202)
Package: tftp-hpa 5.0-18ubuntu1
PackageArchitec
ProcEnviron:
LANGUAGE=en_US:en
PATH=(custom, user)
LANG=en_US.UTF-8
LC_MESSAGES=
SHELL=/bin/bash
ProcVersionSign
Tags: natty
Uname: Linux 2.6.37-9-generic x86_64
UserGroups: adm admin cdrom dialout lpadmin plugdev sambashare
kirkland@x201:~$ tftp dalmation
tftp> get cpuinfo
*** buffer overflow detected ***: tftp terminated
======= Backtrace: =========
/lib/libc.
/lib/libc.
tftp[0x4015f1]
tftp[0x402065]
tftp[0x4036c9]
/lib/libc.
tftp[0x4014d9]
======= Memory map: ========
00400000-00406000 r-xp 00000000 08:01 6297104 /usr/bin/tftp
00605000-00606000 r--p 00005000 08:01 6297104 /usr/bin/tftp
00606000-00607000 rw-p 00006000 08:01 6297104 /usr/bin/tftp
00607000-00627000 rw-p 00000000 00:00 0
0174d000-0176e000 rw-p 00000000 00:00 0 [heap]
7f5078e33000-
7f5078e48000-
7f5079047000-
7f5079048000-
7f5079049000-
7f507905f000-
7f507925e000-
7f507925f000-
7f5079260000-
7f5079262000-
7f5079267000-
7f5079466000-
7f5079467000-
7f5079468000-
7f507946a000-
7f5079669000-
7f507966a000-
7f507966b000-
7f5079677000-
7f5079876000-
7f5079877000-
7f5079878000-
7f50799f2000-
7f5079bf1000-
7f5079bf5000-
7f5079bf6000-
7f5079bfb000-
7f5079df8000-
7f5079e16000-
7f5079e1b000-
7f5079e1c000-
7f5079e1d000-
7fffbc9fb000-
7fffbcbcf000-
ffffffffff60000
Aborted
Changed in tftp-hpa (Ubuntu): | |
status: | New → Fix Committed |
assignee: | nobody → Kees Cook (kees) |
importance: | Undecided → Medium |
Changed in netkit-tftp (Ubuntu): | |
status: | New → Confirmed |
Changed in netkit-tftp (Ubuntu Natty): | |
status: | Confirmed → Fix Committed |
assignee: | nobody → Kees Cook (kees) |
importance: | Undecided → Medium |
apport information