eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
BID:19167
CVE-2006-3838 |Info
eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19167 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3838 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2006 12:00AM |
| Updated: | Sep 05 2006 10:43PM |
| Credit: | Discovered by Cody Pierce, TippingPoint Security Research Team. |
| Vulnerable: |
eIQnetworks Enterprise Security Analyzer 2.1 eIQnetworks Enterprise Security Analyzer 2.0 |
| Not Vulnerable: |
eIQnetworks Enterprise Security Analyzer 2.5 |
Discussion
eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
eIQnetworks Enterprise Security Analyzer Syslog daemon is prone to multiple remote buffer-overflow vulnerabilities.
These issues can facilitate a remote compromise due to arbitrary code execution.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.
eIQnetworks Enterprise Security Analyzer Syslog daemon is prone to multiple remote buffer-overflow vulnerabilities.
These issues can facilitate a remote compromise due to arbitrary code execution.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.
Exploit / POC
eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
The following demonstration exploit is available:
The following demonstration exploit is available:
Solution / Fix
eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
Solution:
The vendor has released version 2.5.0 to address this issue. Please contact the vendor for details.
Solution:
The vendor has released version 2.5.0 to address this issue. Please contact the vendor for details.
References
eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
References:
References: