BugTraq
nmap <= 5.21 is vulnerable to Windows DLL Hijacking Vulnerability. Sep 05 2010 01:27PM
nikhil_uitrgpv yahoo co in (1 replies)
Re: Nmap NOT VULNERABLE to Windows DLL Hijacking Vulnerability. Sep 08 2010 09:38PM
Fyodor (fyodor insecure org)
On Sun, Sep 05, 2010 at 07:27:53AM -0600, nikhil_uitrgpv (at) yahoo.co (dot) in [email concealed] wrote:
> 1. Overview
> nmap <= 5.21 is vulnerable to Windows DLL Hijacking Vulnerability.

Nmap is not vulnerable. DLL hijacking works because of an unfortunate
interaction between apps which register Windows file extensions and
the default Windows DLL search path used for those apps. Nmap does
not, and never has, registered any Windows file extensions. So it
isn't vulnerable to this issue.

> 8. Solution
> Fixed in latest development release.

We have not made a special new development release, nor are we
planning one. We do agree that Windows' default DLL search path
handling is dumb, so we have added code in our source repository to
improve that. It will be included in our next regular release (maybe
in a month or so), along with other proactive security improvements
such as enabling Windows ASLR and DEP support.

Cheers,
Fyodor

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus