Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-0740 PoC — SLRNPull Spool目录命令行参数缓冲区溢出漏洞

Source
Associated Vulnerability
Title:SLRNPull Spool目录命令行参数缓冲区溢出漏洞 (CVE-2002-0740)
Description:SLRN是一款免费开放源代码的新闻阅读工具,由SLRN项目组开发和维护。可以运行在Unix和Linux操作系统下。 SLRN对spool目录名命令行参数的边界检查不够充分,可导致攻击者进行缓冲区溢出攻击。 lsrnpull程序默认以setuid root的属性安装,当slrnpull以-d选项执行时,攻击者可以提供超过4091字节的字符串作为spool目录名传递给-d选项,可导致缓冲溢出,精心构建字符串数据可导致获得root权限。
Description
SLRNPull Spool Directory Command Line Parameter Buffer Overflow Vulnerability
Readme
# CVE-2002-0740
SLRNPull Spool Directory Command Line Parameter Buffer Overflow Vulnerability

Packetstorm publication at https://packetstormsecurity.com/files/25989/slrnpull.overflow.txt.html<br>
Securiteam publication at http://www.securiteam.com/unixfocus/5FP0R0K6UC.html<br>
Securityfocus publication at https://www.securityfocus.com/bid/4569<br>

# Public Exploit:
https://www.securityfocus.com/bid/4569/exploit<br>
https://packetstormsecurity.com/files/26010/pUll.pl.html

# Author
Alex Hernandez aka <em><a href="https://twitter.com/_alt3kx_" rel="nofollow">(@\_alt3kx\_)</a></em>

# The exploit was written by:    
zillion@snosoft.com / safemode.org
File Snapshot

[4.0K] /data/pocs/f87f34da7cf932f7900139c617ee4fd47ac00a49 ├── [ 34K] LICENSE ├── [ 658] README.md └── [ 817] slrnpull-ex.pl 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.