SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerabilities
BID:24773
Info
SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 24773 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3614 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2007 12:00AM |
| Updated: | Nov 15 2007 12:37AM |
| Credit: | Mark Litchfield of NGSSoftware credited with the discovery of these issues. |
| Vulnerable: |
SAP DB 7.5 SAP DB 7.4.3 .7 Beta SAP DB 7.4.3 SAP DB 7.4 .03.30 SAP DB 7.4 SAP DB 7.3 .29 SAP DB 7.3 .00 |
| Not Vulnerable: |
SAP DB 7.6 |
Discussion
SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerabilities
SAP DB Web Server is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized buffer.
Successfully exploiting these issues will allow an attacker to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
SAP DB Web Server is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized buffer.
Successfully exploiting these issues will allow an attacker to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerabilities
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerabilities
References:
References: