Progress and OpenEdge _mprosrv Buffer Overflow Vulnerability
BID:24675
Info
Progress and OpenEdge _mprosrv Buffer Overflow Vulnerability
| Bugtraq ID: | 24675 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2417 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2007 12:00AM |
| Updated: | Jul 13 2007 09:26PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Rsa SecurID Appliance 2.0 Rsa Authentication Manager 6.1 Rsa Authentication Manager 6.0 Rsa ACE/Server 5.2 Progress Software OpenEdge 10 b Progress Database 9.1 D06 Progress Database 9.1 D05 Progress Database 9.1 D Progress Database 9.1 C Progress Database 9.1 B Progress Database 9.1 |
| Not Vulnerable: |
Rsa SecurID Appliance 2.0.1 + hotfix Rsa Authentication Manager 6.1.2 Rsa Authentication Manager 6.0.patch 2 + hotfix Rsa ACE/Server 5.2.patch 1 + hotfix Progress Software OpenEdge 10.1B01 Progress Database 9.1E0422 |
Discussion
Progress and OpenEdge _mprosrv Buffer Overflow Vulnerability
Progress and OpenEdge are prone to a remote buffer-overflow because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker could exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial of service.
The vendor is tracking this issue with number OE00148128.
RSA Security has acknowledged that this vulnerability affects a number of their products. Patches and hotfixes are available to RSA SecurCare Online customers.
Progress and OpenEdge are prone to a remote buffer-overflow because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker could exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial of service.
The vendor is tracking this issue with number OE00148128.
RSA Security has acknowledged that this vulnerability affects a number of their products. Patches and hotfixes are available to RSA SecurCare Online customers.
Exploit / POC
Progress and OpenEdge _mprosrv Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Progress and OpenEdge _mprosrv Buffer Overflow Vulnerability
Solution:
The vendor has released Progress 9.1E0422 and OpenEdge 10.1B01 to address this issue. Please contact the vendor for information on obtaining and applying fixes.
RSA Security has acknowledged that this vulnerability affects a number of their products. Patches and hotfixes are available to RSA SecurCare Online customers.
Solution:
The vendor has released Progress 9.1E0422 and OpenEdge 10.1B01 to address this issue. Please contact the vendor for information on obtaining and applying fixes.
RSA Security has acknowledged that this vulnerability affects a number of their products. Patches and hotfixes are available to RSA SecurCare Online customers.
References
Progress and OpenEdge _mprosrv Buffer Overflow Vulnerability
References:
References:
- OpenEdge Product Page (Progress)
- Progress Database Product Page (Progress)
- RSA SecurCare Online Customer Support (RSA Security)
- Openedge _mprosrv buffer overflow ([email protected])
- Multiple Vendor Progress Server Heap Overflow Vulnerability (TippingPoint Digital Vaccine Laboratories)
- Progress OpenEdge 10.1B01 Service Pack Readme (Progress)