Working Resources BadBlue MFCISAPICommand Remote Buffer Overflow Vulnerability
BID:12673
Info
Working Resources BadBlue MFCISAPICommand Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 12673 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2005 12:00AM |
| Updated: | Feb 26 2005 12:00AM |
| Credit: | Andres Tarasco <atarascosia.es> is credited with the discovery of this issue. |
| Vulnerable: |
Working Resources Inc. BadBlue 2.55 |
| Not Vulnerable: |
Working Resources Inc. BadBlue 2.61 Working Resources Inc. BadBlue 2.60 |
Discussion
Working Resources BadBlue MFCISAPICommand Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects Working Resources BadBlue. This issue is due to a failure of the application to securely copy GET request parameters into finite process buffers.
An attacker may leverage this issue to execute arbitrary code with the privileges of the affected Web server, facilitating a SYSTEM level compromise.
A remote buffer overflow vulnerability affects Working Resources BadBlue. This issue is due to a failure of the application to securely copy GET request parameters into finite process buffers.
An attacker may leverage this issue to execute arbitrary code with the privileges of the affected Web server, facilitating a SYSTEM level compromise.
Exploit / POC
Working Resources BadBlue MFCISAPICommand Remote Buffer Overflow Vulnerability
The following exploits have been made available:
The following exploits have been made available:
Solution / Fix
Working Resources BadBlue MFCISAPICommand Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Working Resources Inc. BadBlue 2.55
Solution:
The vendor has released an upgrade dealing with this issue.
Working Resources Inc. BadBlue 2.55
-
Working Resources Inc. BadBlue 2.61
http://badblue.com/bb95.exe
References
Working Resources BadBlue MFCISAPICommand Remote Buffer Overflow Vulnerability
References:
References:
- BadBlue Product Homepage (Working Resources Inc)