Input validation error in dtach - CVE-2012-3368

 

Input validation error in dtach - CVE-2012-3368

Published: July 4, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43917
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2012-3368
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: crigler
Affected software:
dtach

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach.


How to mitigate CVE-2012-3368

Install update from vendor's website.

Sources