First published: Tue Mar 19 2013(Updated: )
Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the llogin version.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian | =1.25 | |
Debian | =1.26 | |
Debian | =1.27 | |
Debian | =1.28 | |
Debian | =1.29 | |
Debian | =1.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0251 has a high severity due to the potential for remote denial of service and arbitrary code execution.
To fix CVE-2013-0251, upgrade your latd installation to version 1.31 or later.
CVE-2013-0251 can be exploited by sending a long string in the llogin version to the affected latd service.
Versions 1.25 through 1.30 of latd are affected by CVE-2013-0251.
The potential impacts of CVE-2013-0251 include application crashes and possible remote code execution.