CrossWind CyberScheduler websyncd remote Buffer Overflow Vulnerability
BID:2628
Info
CrossWind CyberScheduler websyncd remote Buffer Overflow Vulnerability
| Bugtraq ID: | 2628 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2001 12:00AM |
| Updated: | Apr 17 2001 12:00AM |
| Credit: | This vulnerability was discovered by Enrique A. Sanchez Montellano <[email protected]> on 17 April, 2001 and made public in an advisory posted to BugTraq. |
| Vulnerable: |
CrossWind CyberScheduler 2.1 |
| Not Vulnerable: | |
Discussion
CrossWind CyberScheduler websyncd remote Buffer Overflow Vulnerability
CrossWind CyberScheduler is a scheduling and calendaring package. It consists of two distinct parts for - a set of cgi scripts on a web server and a set of daemons (or services) on a database server. Both parts are available for Windows NT, Linux and a range of UNIX platforms including Solaris.
One of the CyberScheduler daemons 'websyncd' (websyncd.exe on Windows NT) contains an exploitable buffer overflow in its timezone string parser. A timezone string is passed to websyncd by the websync.cgi cgi program (websync.exe on NT) through the tzs form variable.
Because websyncd runs as root, a stack overflow allows arbitrary code execution as root. The overflow occurs before any logon credentials are verified by websync.cgi, so unprivileged remote users can exploit this vulnerability.
CrossWind CyberScheduler is a scheduling and calendaring package. It consists of two distinct parts for - a set of cgi scripts on a web server and a set of daemons (or services) on a database server. Both parts are available for Windows NT, Linux and a range of UNIX platforms including Solaris.
One of the CyberScheduler daemons 'websyncd' (websyncd.exe on Windows NT) contains an exploitable buffer overflow in its timezone string parser. A timezone string is passed to websyncd by the websync.cgi cgi program (websync.exe on NT) through the tzs form variable.
Because websyncd runs as root, a stack overflow allows arbitrary code execution as root. The overflow occurs before any logon credentials are verified by websync.cgi, so unprivileged remote users can exploit this vulnerability.
Exploit / POC
CrossWind CyberScheduler websyncd remote Buffer Overflow Vulnerability
An exploit has been released against x86 Linux versions of CyberScheduler.
In general, a request string like:
/cgi-bin/websync.exe?ed=&Es=7x1x101&un=nahual&hn=lab&rpt=/scheduler/
En_US/WebResources&cbn=/cgi-bin/websync.exe&dow=sun&dmy=Off&tfh=Off
&lan=En_US&ix=0&amd=2&epw=WiXwWFp&mrd=-1&mrc=0&mrb=0&bnv=9&ds=7x1x101
&tzs=<greater than 262 bytes>
Will trigger the overflow in websyncd.
An exploit has been released against x86 Linux versions of CyberScheduler.
In general, a request string like:
/cgi-bin/websync.exe?ed=&Es=7x1x101&un=nahual&hn=lab&rpt=/scheduler/
En_US/WebResources&cbn=/cgi-bin/websync.exe&dow=sun&dmy=Off&tfh=Off
&lan=En_US&ix=0&amd=2&epw=WiXwWFp&mrd=-1&mrc=0&mrb=0&bnv=9&ds=7x1x101
&tzs=<greater than 262 bytes>
Will trigger the overflow in websyncd.
Solution / Fix
CrossWind CyberScheduler websyncd remote Buffer Overflow Vulnerability
Solution:
According to the Defcom Labs, the authors of the advisory, CrossWind was notified on February 15, 2001 and subsequently released a patch for CyberScheduler.
However, the SecurityFocus staff are currently not aware of any publically-available patches for this issue.
If you are aware of more recent information, please mail the SecurityFocus staff at: [email protected] <mailto:[email protected]>.
Solution:
According to the Defcom Labs, the authors of the advisory, CrossWind was notified on February 15, 2001 and subsequently released a patch for CyberScheduler.
However, the SecurityFocus staff are currently not aware of any publically-available patches for this issue.
If you are aware of more recent information, please mail the SecurityFocus staff at: [email protected] <mailto:[email protected]>.
References
CrossWind CyberScheduler websyncd remote Buffer Overflow Vulnerability
References:
References:
- CyberScheduler Data Sheet (CrossWind)