Taken from http://lists.netsys.com/pipermail/full-disclosure/2004-November/029563.html There is buffer overflow in ncplogin and ncpmap in nwclient.c. static void strcpy_cw(wchar_t *w, const char* s) { ~ while ((*w++ = *(const nuint8*)s++) != 0); } NWDSCCODE NWDSCreateContextHandleMnt(NWDSContextHandle* ctx, const NWDSChar * treeName){ ... wchar_t wc_treeName[MAX_DN_CHARS+1]; ~ if (!treeName) ~ return ERR_NULL_POINTER; ~ strcpy_cw (wc_treeName,treeName); Currently i have not managed to successfully exploit this bug on x86. How to reproduce : ncplogin -T `perl -e '{print"a"x"330"}'` ncpmap -T `perl -e '{print"a"x"330"}'` / This issue also affects FC2.
Ping on this issue.
Needs update pushing for FC3