Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RedHat Linux ping Buffer Overflow Vulnerability

ping is a network diagnostic tool shipped with almost every operating system. On unix/linux systems it is usually installed setuid root because it needs to open a raw socket (to send and recieve ICMP messages). The version of ping that ships with RedHat Linux (and quite possibly, though uncomfirmed, others) is vulnerable to a buffer overflow attack. The exact techincal details are not known at this time. It is reported that the overflow involves a static variable, 'buf', though it has not verified whether this this exploitable or not. It is likely that this is non-exploitable.







 

Privacy Statement
Copyright 2008, SecurityFocus