Webalizer - is FreeBSD port vulnerable ?

From: Igor Roshchin (str@giganda.komkon.org)
Date: 04/29/02


Date: Mon, 29 Apr 2002 12:18:55 -0400 (EDT)
From: Igor Roshchin <str@giganda.komkon.org>
To: security@freebsd.org


Hello!

Webalizer is found to have a buffer overflow that is reportedly
remotely exploitable.
http://online.securityfocus.com/archive/1/267551
http://online.securityfocus.com/bid/4504
http://www.mrunix.net/webalizer/news.html

The second link above contains a list of vulnerable versions / OSes.
The only BSD-ish system mentioned is MacOS-X.
Is any of the versions of FreeBSD port vulnerable ?

Best,

Igor

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Remote buffer overflow in Webalizer
    ... Problems: remote buffer overflow ... The Webalizer is a web server log file analysis program ... The webalizer has the ability to perform reverse DNS lookups. ... buffer overflow in the reverse resolving code. ...
    (Bugtraq)
  • Re: Remote buffer overflow in Webalizer
    ... > The Webalizer is a web server log file analysis program ... > The webalizer has the ability to perform reverse DNS lookups. ... > ability to gain remote root acces to a machine, ... > buffer overflow in the reverse resolving code. ...
    (Bugtraq)