Home » Hacking News » Debian DSA 272-1: dietlibc integer overflow

Debian DSA 272-1: dietlibc integer overflow

by Nikola Strahija on March 28th, 2003 An integer overflow has been found in dietlibc. which could possibly be exploited to execute arbitrary code.

Package : dietlibc
Vulnerability : integer overflow
Problem-Type : remote
Debian-specific: no
CVE Id : CAN-2003-0028
CERT advisory : VU#516825 CA-2003-10

eEye Digital Security discovered an integer overflow in the
xdrmem_getbytes() function of glibc, that is also present in dietlibc,
a small libc useful especially for small and embedded systems. This
function is part of the XDR encoder/decoder derived from Sun's RPC
implementation. Depending upon the application, this vulnerability
can cause buffer overflows and could possibly be exploited to execute
arbitray code.

For the stable distribution (woody) this problem has been
fixed in version 0.12-2.5.

The old stable distribution (potato) does not contain dietlibc

For the unstable distribution (sid) this problem has been
fixed in version 0.22-2.

We recommend that you upgrade your dietlibc packages.

Debian GNU/Linux 3.0 alias woody
- --------------------------------

Version: GnuPG v1.2.1 (GNU/Linux)


