[Full-disclosure] [ GLSA 200504-29 ] Pound: Buffer overflow vulnerability

From: Thierry Carrez (koon_at_gentoo.org)
Date: 04/30/05

  • Next message: Sumy: "[Full-disclosure] [Articles] brute forcing - discovering weak logins and more"
    Date: Sat, 30 Apr 2005 16:33:46 +0200
    To: gentoo-announce@lists.gentoo.org
    
    
    
    

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 200504-29
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Severity: High
         Title: Pound: Buffer overflow vulnerability
          Date: April 30, 2005
          Bugs: #90851
            ID: 200504-29

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Pound is vulnerable to a buffer overflow that could lead to the remote
    execution of arbitrary code.

    Background
    ==========

    Pound is a reverse proxy, load balancer and HTTPS front-end.

    Affected packages
    =================

        -------------------------------------------------------------------
         Package / Vulnerable / Unaffected
        -------------------------------------------------------------------
      1 www-servers/pound < 1.8.3 >= 1.8.3

    Description
    ===========

    Steven Van Acker has discovered a buffer overflow vulnerability in the
    "add_port()" function in Pound.

    Impact
    ======

    A remote attacker could send a request for an overly long hostname
    parameter, which could lead to the remote execution of arbitrary code
    with the rights of the Pound daemon process (by default, Gentoo uses
    the "nobody" user to run the Pound daemon).

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All Pound users should upgrade to the latest version:

        # emerge --sync
        # emerge --ask --oneshot --verbose ">=www-servers/pound-1.8.3"

    References
    ==========

      [ 1 ] Original announcement

    http://www.apsis.ch/pound/pound_list/archive/2005/2005-04/1114516112000

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

      http://security.gentoo.org/glsa/glsa-200504-29.xml

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    http://bugs.gentoo.org.

    License
    =======

    Copyright 2005 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    http://creativecommons.org/licenses/by-sa/2.0

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: Sumy: "[Full-disclosure] [Articles] brute forcing - discovering weak logins and more"

    Relevant Pages

    • [ GLSA 200405-08 ] Pound format string vulnerability
      ... arbitrary code with the rights of the Pound process. ... A format string flaw in the processing of syslog messages was ... Gentoo uses the "nobody" user ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • [Full-Disclosure] [ GLSA 200405-08 ] Pound format string vulnerability
      ... arbitrary code with the rights of the Pound process. ... A format string flaw in the processing of syslog messages was ... Gentoo uses the "nobody" user ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • [ GLSA 200405-08 ] Pound format string vulnerability
      ... arbitrary code with the rights of the Pound process. ... A format string flaw in the processing of syslog messages was ... Gentoo uses the "nobody" user ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Bugtraq)
    • Re: Parsing qmail-qread data
      ... If I wanted to view the numbers to the right of the pound signalso, how would I go about doing that? ... done remote user1@xxxxxxxxxxxxx ... print MAIL "$num emails stuck in queue! ...
      (perl.beginners)
    • [TOOL] Pound - Reverse-Proxy and Load-Balancer
      ... Get your security news from a reliable source. ... The Pound program is a reverse ... it will distribute the requests from the client ... one connection even if the back-end server is HTTP/1.0. ...
      (Securiteam)