Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
BID:18647
CVE-2006-3252 |Info
Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 18647 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3252 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2006 12:00AM |
| Updated: | May 30 2007 06:01PM |
| Credit: | Michael Thumann has been credited for the discovery of this vulnerability |
| Vulnerable: |
Algorithmic Research PrivateWire Gateway 3.7 |
| Not Vulnerable: | |
Discussion
Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
PrivateWire online registration is prone to a remote buffer-overflow vulnerability.
The application fails to properly check boundary conditions when handling GET requests.
This issue allows attackers to execute arbitrary machine code in the context of the affected application software.
PrivateWire 3.7 is vulnerable to this issue; previous versions may also be affected.
PrivateWire online registration is prone to a remote buffer-overflow vulnerability.
The application fails to properly check boundary conditions when handling GET requests.
This issue allows attackers to execute arbitrary machine code in the context of the affected application software.
PrivateWire 3.7 is vulnerable to this issue; previous versions may also be affected.
Exploit / POC
Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
The following HTTP GET request is sufficient to demonstrate this issue by crashing the application:
GET /<8160 'A' characters>.
The following exploit code is available:
The following HTTP GET request is sufficient to demonstrate this issue by crashing the application:
GET /<8160 'A' characters>.
The following exploit code is available:
Solution / Fix
Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: mailto:[email protected].
References
Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
References:
References: