FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-12-20 14:15:46 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
4c005a5e-2541-4d95-80a0-00c76919aa66fd_set -- bitmap index overflow in multiple applications

3APA3A reports:

If programmer fails to check socket number before using select() or fd_set macros, it's possible to overwrite memory behind fd_set structure. Very few select() based application actually check FD_SETSIZE value. [...]

Depending on vulnerable application it's possible to overwrite portions of memory. Impact is close to off-by-one overflows, code execution doesn't seems exploitable.


Discovery 2004-12-12
Entry 2005-06-17
Modified 2006-09-03
gatekeeper
< 2.2.1

citadel
< 6.29

3proxy
< 0.5.b

jabber
< 1.4.3.1_1,1

= 1.4.4

bnc
< 2.9.3

rinetd
< 0.62_1

dante
< 1.1.15

bld
< 0.3.3

http://www.gotbnc.com/changes.html#2.9.3
http://www.security.nnov.ru/advisories/sockets.asp
http://marc.theaimsgroup.com/?l=bugtraq&m=110660879328901
4c005a5e-2541-4d95-80a0-00c76919aa66fd_set -- bitmap index overflow in multiple applications

3APA3A reports:

If programmer fails to check socket number before using select() or fd_set macros, it's possible to overwrite memory behind fd_set structure. Very few select() based application actually check FD_SETSIZE value. [...]

Depending on vulnerable application it's possible to overwrite portions of memory. Impact is close to off-by-one overflows, code execution doesn't seems exploitable.


Discovery 2004-12-12
Entry 2005-06-17
Modified 2006-09-03
gatekeeper
< 2.2.1

citadel
< 6.29

3proxy
< 0.5.b

jabber
< 1.4.3.1_1,1

= 1.4.4

bnc
< 2.9.3

rinetd
< 0.62_1

dante
< 1.1.15

bld
< 0.3.3

http://www.gotbnc.com/changes.html#2.9.3
http://www.security.nnov.ru/advisories/sockets.asp
http://marc.theaimsgroup.com/?l=bugtraq&m=110660879328901