Danware NetOp Remote Control Information Disclosure Vulnerability
BID:11710
Info
Danware NetOp Remote Control Information Disclosure Vulnerability
| Bugtraq ID: | 11710 |
| Class: | Design Error |
| CVE: |
CVE-2004-0950 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Martin O'Neal <[email protected]> of Corsaire Security disclosed this vulnerability. |
| Vulnerable: |
Danware Data NetOp 7.60 build 2003246 Danware Data NetOp 7.50 build 2003048 Danware Data NetOp 7.0 1 build 2002291 Danware Data NetOp 6.50 Danware Data NetOp 6.0 |
| Not Vulnerable: |
Danware Data NetOp 7.65 build 2004317 Danware Data NetOp 7.65 build 2004278 |
Discussion
Danware NetOp Remote Control Information Disclosure Vulnerability
It is reported that NetOp Remote Control is susceptible to an information disclosure vulnerability.
This vulnerability reportedly allows remote attackers to discern the name of the user that is logged in and the internal IP address and hostname of the targeted computer. This information may aid malicious users in further attacks.
Versions prior to 7.65 build 2004278 are reported vulnerable to this issue.
It is reported that NetOp Remote Control is susceptible to an information disclosure vulnerability.
This vulnerability reportedly allows remote attackers to discern the name of the user that is logged in and the internal IP address and hostname of the targeted computer. This information may aid malicious users in further attacks.
Versions prior to 7.65 build 2004278 are reported vulnerable to this issue.
Exploit / POC
Danware NetOp Remote Control Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Danware NetOp Remote Control Information Disclosure Vulnerability
Solution:
The vendor has released version 7.65 build 2004278 to address this issue. Users still have to configure the software to disable the 'Public Host Name' option to stop the application from disclosing potentially sensitive information.
Please see the referenced 'Modification Notes - Amelioration History' for further information.
Danware Data NetOp 6.0
Danware Data NetOp 6.50
Danware Data NetOp 7.0 1 build 2002291
Danware Data NetOp 7.50 build 2003048
Danware Data NetOp 7.60 build 2003246
Solution:
The vendor has released version 7.65 build 2004278 to address this issue. Users still have to configure the software to disable the 'Public Host Name' option to stop the application from disclosing potentially sensitive information.
Please see the referenced 'Modification Notes - Amelioration History' for further information.
Danware Data NetOp 6.0
-
Danware Data NetOp Remote Control Latest Version
http://www.netop.com/tech/download/current_rc/windows/updateuk.htm
Danware Data NetOp 6.50
-
Danware Data NetOp Remote Control Latest Version
http://www.netop.com/tech/download/current_rc/windows/updateuk.htm
Danware Data NetOp 7.0 1 build 2002291
-
Danware Data NetOp Remote Control Latest Version
http://www.netop.com/tech/download/current_rc/windows/updateuk.htm
Danware Data NetOp 7.50 build 2003048
-
Danware Data NetOp Remote Control Latest Version
http://www.netop.com/tech/download/current_rc/windows/updateuk.htm
Danware Data NetOp 7.60 build 2003246
-
Danware Data NetOp Remote Control Latest Version
http://www.netop.com/tech/download/current_rc/windows/updateuk.htm
References
Danware NetOp Remote Control Information Disclosure Vulnerability
References:
References:
- Danware Data Homepage (Danware Data)
- Modification Notes - Amelioration History for 7.65 (Danware Data)
- Release Notes (Danware Data)
- Corsaire Security Advisory - Danware NetOp Host multiple information disclosure ("advisories"
)