The server in Toribash 2.71 and earlier does not properly handle long commands, which allows remote attackers to trigger a protocol violation in which data is sent to other clients without a required LF character, as demonstrated by a SAY command. NOTE: the security impact of this violation is not clear, although it probably makes exploitation of CVE-2007-4449 easier.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/477025/100/0/threaded | mailing list |
http://aluigi.org/poc/toribashish.zip | exploit |
http://www.securityfocus.com/bid/25359 | vdb entry exploit |
http://secunia.com/advisories/26507 | third party advisory vendor advisory |
http://securityreason.com/securityalert/3033 | third party advisory |