Debian Security Advisory

DSA-193-1 kdenetwork -- buffer overflow

Date Reported:
11 Nov 2002
Affected Packages:
kdenetwork
Vulnerable:
Yes
Security database references:
In the Bugtraq database (at SecurityFocus): BugTraq ID 6157.
In Mitre's CVE dictionary: CVE-2002-1247.
More information:

iDEFENSE reports a security vulnerability in the klisa package, that provides a LAN information service similar to "Network Neighbourhood", which was discovered by Texonet. It is possible for a local attacker to exploit a buffer overflow condition in resLISa, a restricted version of KLISa. The vulnerability exists in the parsing of the LOGNAME environment variable, an overly long value will overwrite the instruction pointer thereby allowing an attacker to seize control of the executable.

This problem has been fixed in version 2.2.2-14.2 for the current stable distribution (woody) and in version 2.2.2-14.3 for the unstable distribution (sid). The old stable distribution (potato) is not affected since it doesn't contain a kdenetwork package.

We recommend that you upgrade your klisa package immediately.

Fixed in:

Debian GNU/Linux 3.0 (woody)

Source:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2-14.2.dsc
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2-14.2.diff.gz
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_ia64.deb
HP Precision:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_sparc.deb

MD5 checksums of the listed files are available in the original advisory.