eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
BID:19164
CVE-2006-3838 |Info
eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19164 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3838 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2006 12:00AM |
| Updated: | Feb 01 2008 08:17PM |
| Credit: | Discovered by Cody Pierce. |
| Vulnerable: |
Top Layer Network Security Analyzer 0 Securecomputing G2 Security reporter 0 SanMina Viking Multi-Log Manager 0 Fortinet FortiReporter 0 eIQnetworks Enterprise Security Analyzer 2.1 eIQnetworks Enterprise Security Analyzer 2.0 Astaro Report Manager 0 |
| Not Vulnerable: |
iPolicy Security Reporter 0 eIQnetworks Enterprise Security Analyzer 2.5 |
Discussion
eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
eIQnetworks Enterprise Security Analyzer Topology Server is prone to a remote buffer-overflow vulnerability.
This issue can facilitate a remote compromise due to arbitrary code execution.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable. OEM vendors' versions prior to 4.6 are also vulnerable.
eIQnetworks Enterprise Security Analyzer Topology Server is prone to a remote buffer-overflow vulnerability.
This issue can facilitate a remote compromise due to arbitrary code execution.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable. OEM vendors' versions prior to 4.6 are also vulnerable.
Exploit / POC
eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
The following exploit code is available as a module for the Metasploit Framework:
The following exploit code is available as a module for the Metasploit Framework:
Solution / Fix
eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
Solution:
The vendor has released version 2.5.0 to address this issue. Please contact the vendor for details.
Solution:
The vendor has released version 2.5.0 to address this issue. Please contact the vendor for details.
References
eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
References:
References:
- Enterprise Security Analyzer Product Page (eIQnetworks)
- Release Notes Enterprise Security Analyzer v2.5.0 (eIQnetworks)
- eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow (Desai, Deepen)
- TSRT-06-04: eIQnetworks Enterprise Security Analyzer Topology Server Buffer Over ([email protected])