|
|
|
![]() |
Vulnerability Note VU#176363ncompress vulnerable to buffer overflow via long filenameOverviewSome versions of ncompress contain a buffer-overflow vulnerability.I. DescriptionVersions 4.2.4 and earlier of ncompress do not properly handle filenames longer than 1023 characters.II. ImpactBy supplying long filenames to ncompress, an attacker may be able to gain local access to the server or force ncompress to execute arbitrary code.III. SolutionObtain a patch from your vendor.Remove ncompress or remove execute permissions.
References
Thanks to Pavel Kankovsky for reporting this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||