Home » Hacking News » Netstd 3.07-17 multiple remote buffer overflows
Netstd 3.07-17 multiple remote buffer overflows
by Nikola Strahija on May 25th, 2002 It is possible to remotely overflow buffers in several utilities from the package, through owned DNS server. The FQDN obtained from the reply is simply copied into small fixed size buffer, without any check on the length of the answer.
The same problem is present in these utils from the netstd 3.07-17
package:
- linux-ftpd
- pcnfsd
- tftp
- traceroute
- from/to
Public key:
http://spybreak.host.sk