St. Bernard Open File Manager Remote Heap Based Buffer Overflow Vulnerability
BID:26914
Info
St. Bernard Open File Manager Remote Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 26914 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6281 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | Dec 19 2007 12:31AM |
| Credit: | This issue was disclosed by an anonymous researcher in the referenced ZDI advisory. |
| Vulnerable: |
St. Bernard Open File Manager 9.5 |
| Not Vulnerable: |
St. Bernard Open File Manager 9.6 |
Discussion
St. Bernard Open File Manager Remote Heap Based Buffer Overflow Vulnerability
St. Bernard Open File Manager is prone to a remote heap-based buffer-overflow vulnerability because the application fails to properly bound-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects Open File Manager 9.5; other versions may also be vulnerable.
St. Bernard Open File Manager is prone to a remote heap-based buffer-overflow vulnerability because the application fails to properly bound-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects Open File Manager 9.5; other versions may also be vulnerable.
Exploit / POC
St. Bernard Open File Manager Remote Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
St. Bernard Open File Manager Remote Heap Based Buffer Overflow Vulnerability
Solution:
Reports indicate that these vulnerabilities have been fixed in Open File Manager 9.6, but Symantec was not able to verify this information. Please contact the vendor for details.
Solution:
Reports indicate that these vulnerabilities have been fixed in Open File Manager 9.6, but Symantec was not able to verify this information. Please contact the vendor for details.
References
St. Bernard Open File Manager Remote Heap Based Buffer Overflow Vulnerability
References:
References: