FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

junkbuster -- heap corruption vulnerability and configuration modification vulnerability

Affected packages
junkbuster < 2.0.2_3
0 < junkbuster-zlib

Details

VuXML ID 97edf5ab-b319-11d9-837d-000e0c2e438a
Discovery 2005-04-13
Entry 2005-04-22

A Debian advisory reports:

James Ranson discovered that an attacker can modify the referrer setting with a carefully crafted URL by accidently overwriting a global variable.

Tavis Ormandy from the Gentoo Security Team discovered several heap corruptions due to inconsistent use of an internal function that can crash the daemon or possibly lead to the execution of arbitrary code.

References

Bugtraq ID 13146
Bugtraq ID 13147
CVE Name CVE-2005-1108
CVE Name CVE-2005-1109
URL http://www.debian.org/security/2005/dsa-713
URL http://www.gentoo.org/security/en/glsa/glsa-200504-11.xml