header-logo
Suggest Exploit
vendor:
netstd
by:
Willem Pinckaers
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: netstd
Affected Version From: Debian GNU/Linux 1.3 and 2.0
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Linux
1998

Buffer Overflow Vulnerabilities in Debian netstd Package

The netstd package in Debian GNU/Linux is vulnerable to two buffer overflow attacks. The first vulnerability is present in the bootp server, while the second vulnerability exists in the FTP client. The bootp server vulnerability can allow a remote attacker to fully compromise a vulnerable host by exploiting improper bounds checking in the handling of boot file/location specified in a bootp request packet and in the error logging facility. The FTP client vulnerability can be exploited by a local attacker to potentially elevate privileges.

Mitigation:

Apply the necessary patches or updates provided by the vendor. Ensure that the netstd package is up to date.
Source

Exploit-DB raw data: