SAP Internet Graphics Server Remote Buffer Overflow Vulnerability
BID:19470
CVE-2006-4133 |Info
SAP Internet Graphics Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19470 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4133 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2006 12:00AM |
| Updated: | Jul 05 2007 10:17PM |
| Credit: | Mariano Nunez Di Croce from CYBSEC Security and Mark Litchfield from NGSSoftware are credited with discovering this issue. |
| Vulnerable: |
SAP Internet Graphics Server 6.40 Patch 11 SAP Internet Graphics Server 6.40 SAP Internet Graphics Server 7.00 Patch 3 SAP Internet Graphics Server 6.40 Patch 15 |
| Not Vulnerable: |
SAP Internet Graphics Server 7.00 Patch 4 SAP Internet Graphics Server 6.40 Patch 16 |
Discussion
SAP Internet Graphics Server Remote Buffer Overflow Vulnerability
SAP Internet Graphics Server is prone to a remote buffer-overflow vulnerability because it fails to properly verify the size of user-supplied input before copying it into a finite-sized buffer.
A remote attacker can exploit this issue to execute arbitrary code on an affected computer in the context of the affected application. This may facilitate a complete system compromise.
SAP Internet Graphics Server is prone to a remote buffer-overflow vulnerability because it fails to properly verify the size of user-supplied input before copying it into a finite-sized buffer.
A remote attacker can exploit this issue to execute arbitrary code on an affected computer in the context of the affected application. This may facilitate a complete system compromise.
Exploit / POC
SAP Internet Graphics Server Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
SAP Internet Graphics Server Remote Buffer Overflow Vulnerability
Solution:
The vendor has released updates to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released updates to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
References
SAP Internet Graphics Server Remote Buffer Overflow Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Internet Graphics Server XSS and Heap Overflow (Mark Litchfield)
- CYBSEC - Security Pre-Advisory: SAP Internet Graphics Service (IGS) Remote Buffe (CYBSEC)
- CYBSEC Security Advisory: SAP Internet Graphics Service (IGS) Remote Buffer Over (CYBSEC)
- SAP Internet Graphics Service (IGS) Remote Buffer Overflow (CYBSEC)