This has been fixed in the current version in CVS branch nsd_v3_r3_p0
(post-AOLserver 3.4.2) and can be used for any affected version.  See:

 http://sourceforge.net/tracker/?func=detail&atid=103152&aid=531946&group_id=3152


Kris


On Thursday, [EMAIL PROTECTED] wrote:
>
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>________________________________________________________________________
>SECURITY ADVISORY                                            INTEXXIA(c)
>30 01 2002                                               ID #1052-300102
>________________________________________________________________________
>TITLE   : AOLServer DB Proxy Daemon Format String Vulnerability
>CREDITS : Guillaume Pelat / INTEXXIA
>________________________________________________________________________
>
>
>SYSTEM AFFECTED
>===============
>
>        AOLServer 3.4.2
>        AOLServer 3.4.1
>        AOLServer 3.4
>        AOLServer 3.3.1
>        AOLServer 3.2.1
>        AOLServer 3.2
>        AOLServer 3.1
>        AOLServer 3.0
>
>
>________________________________________________________________________
>
>
>DESCRIPTION
>===========
>
>        The Laboratory  intexxia found  a format string vulnerability in
>the AOL Server external database driver proxy daemon API that could lead
>to a privilege escalation.
>
>
>________________________________________________________________________
>
>
>DETAILS
>=======
>
>        AOL Server provides  an API  to develop external database driver
>proxy daemons. Those daemons are linked to a library (libnspd.a).
>
>The Laboratory  intexxia found  a format  string and  a buffer  overflow
>vulnerability in  the 'Ns_PdLog'  function of  the  library.  Successful
>exploitation of the bug could allow an  attacker to execute code and get
>access on the system.
>
>As a result, all  the External Driver Proxy Daemons using the 'Ns_PdLog'
>function  with  the  'Error'   or  'Notice'  parameter  are  potentially
>vulnerable.
>
>
>________________________________________________________________________
>
>
>SOLUTION
>========
>
>        There is  no  official  solution  for  the  moment. However, the
>Laboratory intexxia developped a patch  that address  this issue.  It is
>attached to this bulletin.
>
>
>________________________________________________________________________
>
>
>VENDOR STATUS
>=============
>
>        14-03-2002 : This bulletin was sent to the developpement team.
>
>
>________________________________________________________________________
>
>
>LEGALS
>======
>
>        AOL Server is a registered trademark.
>
>
>        This  advisory  is  being  provided  to  you  under  the  policy
>documented    at   http://www.wiretrip.net/rfp/policy.html.    You   are
>encouraged  to  read  this  policy.  However,  in the interim, you  have
>approximately  a week  to respond  to this  initial email.  This  policy
>encourages open communication, and we look forward to  work with  you on
>resolving the problem detailed above.
>
>
>        Intexxia provides this  information  as a public service and "as
>is". Intexxia  will not be  held accountable for  any damage or distress
>caused by the proper or improper usage of these materials.
>
>
>        (c) intexxia 2002.  This information is  classified confidential
>which means that  you cannot redistribute it in its actual state outside
>your internal organisation and/or constituency (specifically involved in
>the incident).
>
>
>________________________________________________________________________
>
>
>CONTACT
>=======
>
>CERT intexxia                                          [EMAIL PROTECTED]
>INTEXXIA                                         http://www.intexxia.com
>171, av. Georges Clemenceau                 Standard : +33 1 55 69 49 10
>92024 Nanterre Cedex - France                    Fax : +33 1 55 69 78 80
>
>-----BEGIN PGP SIGNATURE-----
>Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
>
>iQA/AwUBPJCVe02N8BNyNDXLEQLVEQCgyri4l/HZaZ4q9OH4JjczkbTSeJIAoIsU
>nyV8mUYXZdbmKDPnjsQ0Mbc7
>=03WU
>-----END PGP SIGNATURE-----

--
Kriston Rehberg
America Online, Inc.

Reply via email to