Exploitable buffer overflow in bootpd | Linux Today

Exploitable buffer overflow in bootpd

Written By
Web Webster
Web Webster
Dec 13, 1998

Willem
Pinckaers
reported to BUGTRAQ:

Introduction.

While browsing the bootpd source of version 2.4.3, shipped with
most recent unices, an overflow bug was found in the handling of
the boot file/location specified in a bootp request packet, and a
second bug exists in the error logging facility (which is only
available when running with a debug level bigger than 2). This bug
introduces a major security hole, including the possibility of
remote root access.

Vulnerable Systems.

All systems running bootpd 2.4.3.
All systems which are using a bootp daemon derived from the bootp
daemon originally released at Stanford University.
We don’t know of any unix system that is NOT vulnerable to this
problem.
Exploit code was tested against linux systems running debian 2.0
(glibc), and debian 1.3, both running bootpd 2.4.3.

————————— Technical information and exploit
removed.

Red Hat also ships bootp 2.4.3. Watch Linux Today for any
vendor updates as we receive them

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.