Big Brother bbd.c Buffer Overflow Vulnerability
From a message to Bugtraq on July 16, 2000 by Loki <firstname.lastname@example.org>
Required only on hosts that are defined as BBDISPLAY.
Don't forget hosts that were at one point BBDISPLAY
but were turned into a client only host afterwards.
1) If you have BBLOGSTATUS=DYNAMIC set in etc/bbdef.sh,
then download BB 1.4h2 and extract bb-hostsvc.sh. Replace
the script in the cgi-bin and set the BBHOME variable
in the bb-hostsvc.sh script. Make sure the script
has the proper permissions.
2) If you have BBLOGSTATUS=STATIC or BBLOGSTATUS=TEXT
set in etc/bbdef.sh, then just remove the bb-hostsvc.sh
from the cgi-bin directory as it is not required for
3) Set BBLOGSTATUS=STATIC in bbdef.sh and remove the
script as described in 2).