This has been fixed in the current version in CVS branch nsd_v3_r3_p0 (post-AOLserver 3.4.2) and can be used for any affected version. See:
http://sourceforge.net/tracker/?func=detail&atid=103152&aid=531946&group_id=3152 Kris On Thursday, [EMAIL PROTECTED] wrote: > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >________________________________________________________________________ >SECURITY ADVISORY INTEXXIA(c) >30 01 2002 ID #1052-300102 >________________________________________________________________________ >TITLE : AOLServer DB Proxy Daemon Format String Vulnerability >CREDITS : Guillaume Pelat / INTEXXIA >________________________________________________________________________ > > >SYSTEM AFFECTED >=============== > > AOLServer 3.4.2 > AOLServer 3.4.1 > AOLServer 3.4 > AOLServer 3.3.1 > AOLServer 3.2.1 > AOLServer 3.2 > AOLServer 3.1 > AOLServer 3.0 > > >________________________________________________________________________ > > >DESCRIPTION >=========== > > The Laboratory intexxia found a format string vulnerability in >the AOL Server external database driver proxy daemon API that could lead >to a privilege escalation. > > >________________________________________________________________________ > > >DETAILS >======= > > AOL Server provides an API to develop external database driver >proxy daemons. Those daemons are linked to a library (libnspd.a). > >The Laboratory intexxia found a format string and a buffer overflow >vulnerability in the 'Ns_PdLog' function of the library. Successful >exploitation of the bug could allow an attacker to execute code and get >access on the system. > >As a result, all the External Driver Proxy Daemons using the 'Ns_PdLog' >function with the 'Error' or 'Notice' parameter are potentially >vulnerable. > > >________________________________________________________________________ > > >SOLUTION >======== > > There is no official solution for the moment. However, the >Laboratory intexxia developped a patch that address this issue. It is >attached to this bulletin. > > >________________________________________________________________________ > > >VENDOR STATUS >============= > > 14-03-2002 : This bulletin was sent to the developpement team. > > >________________________________________________________________________ > > >LEGALS >====== > > AOL Server is a registered trademark. > > > This advisory is being provided to you under the policy >documented at http://www.wiretrip.net/rfp/policy.html. You are >encouraged to read this policy. However, in the interim, you have >approximately a week to respond to this initial email. This policy >encourages open communication, and we look forward to work with you on >resolving the problem detailed above. > > > Intexxia provides this information as a public service and "as >is". Intexxia will not be held accountable for any damage or distress >caused by the proper or improper usage of these materials. > > > (c) intexxia 2002. This information is classified confidential >which means that you cannot redistribute it in its actual state outside >your internal organisation and/or constituency (specifically involved in >the incident). > > >________________________________________________________________________ > > >CONTACT >======= > >CERT intexxia [EMAIL PROTECTED] >INTEXXIA http://www.intexxia.com >171, av. Georges Clemenceau Standard : +33 1 55 69 49 10 >92024 Nanterre Cedex - France Fax : +33 1 55 69 78 80 > >-----BEGIN PGP SIGNATURE----- >Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com> > >iQA/AwUBPJCVe02N8BNyNDXLEQLVEQCgyri4l/HZaZ4q9OH4JjczkbTSeJIAoIsU >nyV8mUYXZdbmKDPnjsQ0Mbc7 >=03WU >-----END PGP SIGNATURE----- -- Kriston Rehberg America Online, Inc.
