RSA Authentication Agent IISWebAgentIF.DLL Remote Stack Based Buffer Overflow Vulnerability
BID:26424
Info
RSA Authentication Agent IISWebAgentIF.DLL Remote Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 26424 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-4734 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2005 12:00AM |
| Updated: | Nov 14 2007 05:04PM |
| Credit: | H.D Moore is credited with the discovery of this vulnerability. |
| Vulnerable: |
Rsa Authentication Agent 5.3 Rsa Authentication Agent 5.2 |
| Not Vulnerable: | |
Discussion
RSA Authentication Agent IISWebAgentIF.DLL Remote Stack Based Buffer Overflow Vulnerability
RSA Authentication Agent is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue on an affected computer to execute code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
RSA WebAgent 5.2 and 5.3 for Web for Microsoft IIS are vulnerable; other versions may also be affected.
RSA Authentication Agent is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue on an affected computer to execute code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
RSA WebAgent 5.2 and 5.3 for Web for Microsoft IIS are vulnerable; other versions may also be affected.
Exploit / POC
RSA Authentication Agent IISWebAgentIF.DLL Remote Stack Based Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
RSA Authentication Agent IISWebAgentIF.DLL Remote Stack Based Buffer Overflow Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
RSA Authentication Agent IISWebAgentIF.DLL Remote Stack Based Buffer Overflow Vulnerability
References:
References:
- RSA IISWebagent Redirect Vulnerability (H.D Moore)
- RSA WebAgent Homepage (RSA)