OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] SETIhome remotely exploitable buffer overflow

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Mon Apr 07 2003 - 06:18:34 CDT


TITLE:
SETIhome remotely exploitable buffer overflow

READ ONLINE:
http://www.secunia.com/advisories/8532/

CRITICAL:
Moderately critical

IMPACT:
Exposure of system information, System access

WHERE:
From remote

SOFTWARE:
SETIhome 3.x

DESCRIPTION:
SETIhome uses http to communicate with the SETIhome server.

Users who are able to sniff traffic are able to see details about the
processor and operating system.

Users who are able to perform a man-in-the-middle attack or
manipulate DNS records, may return a malicious server response which
causes a buffer overflow in the SETIhome client.

Exploit code has been released.

SOLUTION:
SETIhome has released a new version:

http://setiathome.berkeley.edu/download.html

REPORTED BY / CREDITS:
Berend-Jan Wever

ORIGINAL ADVISORY:
http://spoor12.edup.tudelft.nl/

OTHER REFERENCES:
http://setiathome.berkeley.edu/version308.html

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------