SynCE 'vdccm' Daemon Remote Command Injection Vulnerability
BID:27178
Info
SynCE 'vdccm' Daemon Remote Command Injection Vulnerability
| Bugtraq ID: | 27178 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1136 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2008 12:00AM |
| Updated: | Mar 10 2008 01:01PM |
| Credit: | Alfredo Ortega and Oren Isacson from Core Security Technologies are credited with the discovery of this issue. |
| Vulnerable: |
SynCE SynCE 0.92 Red Hat Fedora 8 |
| Not Vulnerable: |
SynCE SynCE 0.10.1 SynCE SynCE 0.91 |
Discussion
SynCE 'vdccm' Daemon Remote Command Injection Vulnerability
SynCE is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary commands in the context of the application, facilitating the remote compromise of affected computers.
SynCE 0.92 is vulnerable; other versions may also be affected.
SynCE is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary commands in the context of the application, facilitating the remote compromise of affected computers.
SynCE 0.92 is vulnerable; other versions may also be affected.
Exploit / POC
SynCE 'vdccm' Daemon Remote Command Injection Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
SynCE 'vdccm' Daemon Remote Command Injection Vulnerability
Solution:
The vendor has released an update that addresses this issue. Please see the references for more information.
SynCE SynCE 0.92
Solution:
The vendor has released an update that addresses this issue. Please see the references for more information.
SynCE SynCE 0.92
-
SynCE SynCE-vdccm-0.10.1.tar.gz
http://downloads.sourceforge.net/synce/vdccm-0.10.1.tar.gz?modtime=119 8094834&big_mirror=0
References
SynCE 'vdccm' Daemon Remote Command Injection Vulnerability
References:
References:
- SynCE Homepage (SynCE)
- CORE-2007-1106: SynCE Remote Command Injection (CORE Security Technologies Advisories
)