WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Authentication Bypass Vulnerability
BID:27614
Info
WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Authentication Bypass Vulnerability
| Bugtraq ID: | 27614 |
| Class: | Unknown |
| CVE: |
CVE-2008-5159 CVE-2008-5158 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Luigi Auriemma is credited with the discovery of these issues. |
| Vulnerable: |
Client Software WinCom LPD Total 3.0.2.623 |
| Not Vulnerable: | |
Discussion
WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Authentication Bypass Vulnerability
WinComLPD Total is prone to multiple vulnerabilities, including buffer-overflow vulnerabilities and an authentication-bypass vulnerability.
Successfully exploiting these issues will allow an attacker to perform unauthorized actions or execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect WinComLPD Total 3.0.2.623; other versions may also be vulnerable.
WinComLPD Total is prone to multiple vulnerabilities, including buffer-overflow vulnerabilities and an authentication-bypass vulnerability.
Successfully exploiting these issues will allow an attacker to perform unauthorized actions or execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect WinComLPD Total 3.0.2.623; other versions may also be vulnerable.
Exploit / POC
WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Authentication Bypass Vulnerability
The following proof-of-concept exploit code is available:
The following proof-of-concept exploit code is available:
Solution / Fix
WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Authentication Bypass Vulnerability
References:
References:
- WinCom LPD Total Homepage (Client Software)
- Multiple vulnerabilities in WinCom LPD Total 3.0.2.623 (Luigi Auriemma
)