|
Big Brother bbd.c Buffer Overflow Vulnerability
Solution: From a message to Bugtraq on July 16, 2000 by Loki <loki.loa@subdimensional.com> Solution: Required only on hosts that are defined as BBDISPLAY. Don't forget hosts that were at one point BBDISPLAY but were turned into a client only host afterwards. 1) If you have BBLOGSTATUS=DYNAMIC set in etc/bbdef.sh, then download BB 1.4h2 and extract bb-hostsvc.sh. Replace the script in the cgi-bin and set the BBHOME variable in the bb-hostsvc.sh script. Make sure the script has the proper permissions. 2) If you have BBLOGSTATUS=STATIC or BBLOGSTATUS=TEXT set in etc/bbdef.sh, then just remove the bb-hostsvc.sh from the cgi-bin directory as it is not required for these setups. 3) Set BBLOGSTATUS=STATIC in bbdef.sh and remove the script as described in 2). |
|
|
Privacy Statement |