NetSupport Manager Initial Client Connection Buffer Overflow Vulnerability
BID:25932
Info
NetSupport Manager Initial Client Connection Buffer Overflow Vulnerability
| Bugtraq ID: | 25932 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5252 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | sxkeebler and r@b13$ are credited with the discovery of this vulnerability. |
| Vulnerable: |
NetSupport NetSupport School 9.02 NetSupport NetSupport Manager 10.20 NetSupport NetSupport Manager 10.00 |
| Not Vulnerable: |
NetSupport NetSupport School 9.2.5 NetSupport NetSupport Manager 10.20.5 |
Discussion
NetSupport Manager Initial Client Connection Buffer Overflow Vulnerability
NetSupport Manager is prone to a unspecified buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application or crash the application, denying service to legitimate users.
NetSupport Manager is prone to a unspecified buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application or crash the application, denying service to legitimate users.
Exploit / POC
NetSupport Manager Initial Client Connection Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NetSupport Manager Initial Client Connection Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory along with a fix to address this issue. Please see the references for more information.
Solution:
The vendor has released an advisory along with a fix to address this issue. Please see the references for more information.
References
NetSupport Manager Initial Client Connection Buffer Overflow Vulnerability
References:
References: