CVE-2010-1938

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:6:stable:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:release:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:release_p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:release_p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:release_p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:release_p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:stable:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:beta_4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:current:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:release:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:release-p12:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:release-p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:release-p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:releng:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:stable:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0-release:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0_beta4:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0_releng:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:pre-release:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:release-p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:release-p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:release-p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:release-p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:release-p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:stable:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.2:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.2:pre-release:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.2:stable:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.1-prerelease:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:nrl:opie:*:test1:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.2:*:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.3:*:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.4:*:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.10:*:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.11:*:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.21:*:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.22:*:*:*:*:*:*:*
cpe:2.3:a:nrl:opie:2.32:*:*:*:*:*:*:*

History

21 Nov 2024, 01:15

Type Values Removed Values Added
References () http://blog.pi3.com.pl/?p=111 - () http://blog.pi3.com.pl/?p=111 -
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584932 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584932 -
References () http://secunia.com/advisories/39963 - Vendor Advisory () http://secunia.com/advisories/39963 - Vendor Advisory
References () http://secunia.com/advisories/39966 - Vendor Advisory () http://secunia.com/advisories/39966 - Vendor Advisory
References () http://secunia.com/advisories/45136 - () http://secunia.com/advisories/45136 -
References () http://security.FreeBSD.org/advisories/FreeBSD-SA-10:05.opie.asc - Vendor Advisory () http://security.FreeBSD.org/advisories/FreeBSD-SA-10:05.opie.asc - Vendor Advisory
References () http://securityreason.com/achievement_securityalert/87 - () http://securityreason.com/achievement_securityalert/87 -
References () http://securityreason.com/securityalert/7450 - () http://securityreason.com/securityalert/7450 -
References () http://securitytracker.com/id?1024040 - () http://securitytracker.com/id?1024040 -
References () http://securitytracker.com/id?1025709 - () http://securitytracker.com/id?1025709 -
References () http://site.pi3.com.pl/adv/libopie-adv.txt - () http://site.pi3.com.pl/adv/libopie-adv.txt -
References () http://www.debian.org/security/2011/dsa-2281 - () http://www.debian.org/security/2011/dsa-2281 -
References () http://www.exploit-db.com/exploits/12762 - () http://www.exploit-db.com/exploits/12762 -
References () http://www.securityfocus.com/bid/40403 - () http://www.securityfocus.com/bid/40403 -

Information

Published : 2010-05-28 18:30

Updated : 2024-11-21 01:15


NVD link : CVE-2010-1938

Mitre link : CVE-2010-1938

CVE.ORG link : CVE-2010-1938


JSON object : View

Products Affected

freebsd

  • freebsd

nrl

  • opie
CWE
CWE-189

Numeric Errors