CVE-2012-3368

NameCVE-2012-3368
DescriptionInteger signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow
Debian Bugs625302

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dtach (PTS)stretch0.9-1fixed
buster0.9-4fixed
bullseye, sid0.9-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dtachsourcesqueeze0.8-2+squeeze1
dtachsource(unstable)0.8-2.1low625302

Notes

http://sourceforge.net/tracker/?func=detail&aid=3517812&group_id=36489&atid=417357
http://sourceforge.net/tracker/download.php?group_id=36489&atid=417357&file_id=441195&aid=3517812
https://bugzilla.redhat.com/show_bug.cgi?id=812551
https://bugzilla.redhat.com/show_bug.cgi?id=835849

Search for package or bug name: Reporting problems