eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
BID:19165
CVE-2006-3838 |Info
eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
| Bugtraq ID: | 19165 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3838 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2006 12:00AM |
| Updated: | Sep 05 2006 10:28PM |
| Credit: | Discovered by Titon, JxT, KF and the rest of Bastard Labs. |
| Vulnerable: |
eIQnetworks Enterprise Security Analyzer 2.1 eIQnetworks Enterprise Security Analyzer 2.0 |
| Not Vulnerable: |
eIQnetworks Enterprise Security Analyzer 2.5 |
Discussion
eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
eIQnetworks Enterprise Security Analyzer Syslog daemon is prone to a remote buffer-overflow vulnerability.
This issue can facilitate a remote compromise due to arbitrary code execution.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.
eIQnetworks Enterprise Security Analyzer Syslog daemon is prone to a remote buffer-overflow vulnerability.
This issue can facilitate a remote compromise due to arbitrary code execution.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.
Exploit / POC
eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
Solution:
The vendor has released version 2.5.0 to address this issue. Please contact the vendor for details.
Solution:
The vendor has released version 2.5.0 to address this issue. Please contact the vendor for details.
References
eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
References:
References: