Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 220911
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Joel <smoothp9nguin@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 220911 depends on: Show dependency tree
Bug 220911 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-05-08 12:07 0000
Secunia:

Description:
Some vulnerabilities have been reported in rdesktop, which can be exploited by
malicious people to compromise a user's system.

1) An integer underflow error in iso.c when processing RDP requests can be
exploited to cause a heap-based buffer overflow.

2) An input validation error in rdp.c when processing RDP redirect requests can
be exploited to cause a BSS-based buffer overflow.

3) A signedness error within "xrealloc()" in rdesktop.c can be exploited to
cause a heap-based buffer overflow.

Successful exploitation allows execution of arbitrary code but requires that a
user is tricked into connecting to a malicious RDP server.

The vulnerabilities are reported in version 1.5.0. Other versions may also be
affected.

Solution:
Fixed in the CVS repository.
http://rdesktop.cvs.sourceforge.net/r...p;diff_format=h&pathrev=HEAD#l101
http://rdesktop.cvs.sourceforge.net/r...annotate=1.102&pathrev=HEAD#l1337
http://rdesktop.cvs.sourceforge.net/r...amp;tr2=1.118&diff_format=h#l1134

Original Advisory:
iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=696
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=697
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=698

------- Comment #1 From Robert Buchholz 2008-05-14 16:43:00 0000 -------
PoCs:
http://milw0rm.com/exploits/5561
http://milw0rm.com/exploits/5585

Martin is retiring per bug #159513, so I bumped to the freshly released 1.6.0.
It contains all the fixes "linked" above.

------- Comment #2 From Robert Buchholz 2008-05-14 16:43:22 0000 -------
Arches, please test and mark stable:
=net-misc/rdesktop-1.6.0
Target keywords : "alpha amd64 hppa ia64 ppc ppc64 release sparc x86"

------- Comment #3 From Markus Rothe 2008-05-14 17:03:20 0000 -------
ppc64 stable

------- Comment #4 From Markus Meier 2008-05-14 20:17:57 0000 -------
amd64/x86 stable

------- Comment #5 From Jeroen Roovers 2008-05-15 04:04:34 0000 -------
Stable for HPPA.

------- Comment #6 From Ferris McCormick 2008-05-16 15:24:49 0000 -------
Sparc done.

------- Comment #7 From Tobias Scherbaum 2008-05-16 19:40:30 0000 -------
ppc stable

------- Comment #8 From Raúl Porcel 2008-05-17 09:52:48 0000 -------
ia64 stable, Tobias will do alpha later today

------- Comment #9 From Tobias Klausmann 2008-05-17 13:32:00 0000 -------
Stable on alpha.

------- Comment #10 From Peter Volkov 2008-05-18 15:26:38 0000 -------
Fixed in release snapshot.

------- Comment #11 From Pierre-Yves Rofes 2008-06-14 19:16:08 0000 -------
GLSA 200806-04

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug