Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Gentoo Local Security Checks --> Category: infos

[GLSA-200701-20] Centericq: Remote buffer overflow in LiveJournal handling Vulnerability Scan


Vulnerability Scan Summary
Centericq: Remote buffer overflow in LiveJournal handling

Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200701-20
(Centericq: Remote buffer overflow in LiveJournal handling)


When interfacing with the LiveJournal service, Centericq does not
appropriately allocate memory for incoming data, in some cases creating
a buffer overflow.

Impact

A possible hacker could entice a user to connect to an unofficial LiveJournal
server causing Centericq to read specially crafted data from the
server, which could lead to the execution of arbitrary code with the
rights of the user running Centericq.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0160


Solution:
Currently, Centericq is unmaintained. As such, Centericq has been
masked in Portage until it is again maintained.
# emerge --ask --verbose --unmerge "net-im/centericq"


Threat Level: Medium


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.