Rabox WinLPD Remote Buffer Overflow Vulnerability
BID:19011
CVE-2006-3670 |Info
Rabox WinLPD Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19011 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2006 12:00AM |
| Updated: | Jul 28 2006 05:57PM |
| Credit: | Pablo Neuquen <[email protected]> discovered this vulnerabillity. |
| Vulnerable: |
Rabox Winlpd 1.26 Rabox Winlpd 1.2 build 1076 |
| Not Vulnerable: | |
Discussion
Rabox WinLPD Remote Buffer Overflow Vulnerability
Winlpd is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable application. Since this application listens on TCP port 515, it requires elevated privileges. Successfully exploiting this issue, therefore, likely facilitates the complete compromise of affected computers.
Winlpd version 1.2, build 1076 is vulnerable to this issue; other versions may also be affected.
Winlpd is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable application. Since this application listens on TCP port 515, it requires elevated privileges. Successfully exploiting this issue, therefore, likely facilitates the complete compromise of affected computers.
Winlpd version 1.2, build 1076 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Rabox WinLPD Remote Buffer Overflow Vulnerability
The following exploit is available to demonstrate this issue:
The following exploit is available to demonstrate this issue:
Solution / Fix
Rabox WinLPD Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Rabox WinLPD Remote Buffer Overflow Vulnerability
References:
References:
- Winlpd Product Page (Rabox)
- Buffer Overflow Vulnerability in Winlpd ( Meftun)