Executive Summary

Summary
TitleNew barnowl packages fix arbitrary code execution
Informations
NameDSA-2102First vendor Publication2010-09-03
VendorDebianLast vendor Modification2010-09-03
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score7.5Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

It has been discovered that in barnowl, a curses-based instant-messaging client, the return codes of calls to the ZPending and ZReceiveNotice functions in libzephyr were not checked, allowing attackers to cause a denial of service (crash of the application), and possibly execute arbitrary code.

For the stable distribution (lenny), this problem has been fixed in version 1.0.1-4+lenny2.

For the testing distribution (squeeze), this problem has been fixed in version 1.6.2-1.

For the unstable distribution (sid), this problem has been fixed in version 1.6.2-1.

We recommend that you upgrade your barnowl packages.

Original Source

Url : http://www.debian.org/security/2010/dsa-2102

CWE : Common Weakness Enumeration

idName
CWE-20Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application21

Open Source Vulnerability Database (OSVDB)

idDescription
66887BarnOwl libzephyr Multiple Function Return Code Check Weakness Remote DoS

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-11 00:43:51
  • Multiple Updates