MiniShare Server Remote Buffer Overflow Vulnerability
BID:11620
Info
MiniShare Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11620 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-2271 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2004 12:00AM |
| Updated: | Dec 29 2008 09:22PM |
| Credit: | This vulnerability was disclosed by "class 101" <[email protected]>. |
| Vulnerable: |
MiniShare Minimal HTTP Server 1.4.1 |
| Not Vulnerable: | |
Discussion
MiniShare Server Remote Buffer Overflow Vulnerability
MiniShare is prone to a remote buffer-overflow vulnerability because it fails to sufficiently verify buffer boundaries before copying user-supplied data.
Exploiting this vulnerability allows remote attackers to execute arbitrary code in the context of the affected application.
MiniShare 1.4.1 is reported vulnerable; other versions may also be affected.
MiniShare is prone to a remote buffer-overflow vulnerability because it fails to sufficiently verify buffer boundaries before copying user-supplied data.
Exploiting this vulnerability allows remote attackers to execute arbitrary code in the context of the affected application.
MiniShare 1.4.1 is reported vulnerable; other versions may also be affected.
Exploit / POC
MiniShare Server Remote Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Proof-of-concept exploits are available, including an exploit for the Metasploit Framework (minishare_get_overflow.pm).
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Proof-of-concept exploits are available, including an exploit for the Metasploit Framework (minishare_get_overflow.pm).
Solution / Fix
MiniShare Server Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MiniShare Server Remote Buffer Overflow Vulnerability
References:
References:
- Project Home Page (MiniShare)
- Vulnerability In MiniShare 1.4.1 (MiniShare)