LWN.net Logo

ident2 buffer overflow

Package(s):ident2 CVE #(s):CAN-2004-0408
Created:April 22, 2004 Updated:April 28, 2004
Description: Jack <jack -AT- rapturesecurity.org> discovered a buffer overflow in ident2, an implementation of the ident protocol (RFC1413), where a buffer in the child_service function was slightly too small to hold all of the data which could be written into it. This vulnerability could be exploited by a remote attacker to execute arbitrary code with the privileges of the ident2 daemon (by default, the "identd" user).
Alerts:
Debian DSA-494-1 2004-04-21

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds