|
|
|
Vulnerability Note VU#619812UMN Gopher vulnerable to buffer overflow via overly long "+VIEWS:"OverviewThe University of Minnesota Gopher client may be vulnerable to a buffer overflow when handling overly long "+VIEWS:" reply messages sent from a malicious server.I. DescriptionThe UMN Gopher suite includes a Gopher client for navigating Gopherspace. However, the Gopher client may incorrectly handle a reply message from the server with overly long "+VIEWS:" content. The VIfromLine() function contains a boundary error when copying input to a buffer on the stack, which may cause a stack-based buffer overflow condition.Successful exploitation may allow remote arbitrary code execution. If the user is running the gopher client with elevated privileges, the system may be compromised to the point of the attacking taking total control. Unless a specific need is known for Gopher support in your web browser or operating system, either disable support in the application or remove the Gopher application(s) from the system. This will help to mitigate future attacks should the Gopher code in question not be updated in a timely fashion.
References
Thanks to vade79 for reporting this vulnerability. This document was written by Ken MacInnis.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||