Overview
Some versions of ncompress contain a buffer-overflow vulnerability.
Description
Versions 4.2.4 and earlier of ncompress do not properly handle filenames longer than 1023 characters. |
Impact
By supplying long filenames to ncompress, an attacker may be able to gain local access to the server or force ncompress to execute arbitrary code. |
Solution
Obtain a patch from your vendor. |
Remove ncompress or remove execute permissions. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Pavel Kankovsky for reporting this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
CVE IDs: | None |
Severity Metric: | 0.92 |
Date Public: | 2001-11-20 |
Date First Published: | 2002-08-01 |
Date Last Updated: | 2002-08-10 19:45 UTC |
Document Revision: | 11 |