CVE-2012-3368

NameCVE-2012-3368
DescriptionInteger signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs625302

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dtach (PTS)buster0.9-4fixed
sid, trixie, bookworm, bullseye0.9-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dtachsourcesqueeze0.8-2+squeeze1
dtachsource(unstable)0.8-2.1low625302

Notes

http://sourceforge.net/tracker/?func=detail&aid=3517812&group_id=36489&atid=417357
http://sourceforge.net/tracker/download.php?group_id=36489&atid=417357&file_id=441195&aid=3517812
https://bugzilla.redhat.com/show_bug.cgi?id=812551
https://bugzilla.redhat.com/show_bug.cgi?id=835849

Search for package or bug name: Reporting problems