Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
BID:27896
Info
Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 27896 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0871 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Luigi Auriemma is credited with the discovery of these issues. |
| Vulnerable: |
Now Wireless Now SMS & MMS Gateway 2007.6.27 |
| Not Vulnerable: |
Now Wireless Now SMS & MMS Gateway 2008 |
Discussion
Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
Now SMS/MMS Gateway is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting these issues will allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect Now SMS/MMS Gateway 2007.06.27 and prior versions.
Now SMS/MMS Gateway is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting these issues will allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect Now SMS/MMS Gateway 2007.06.27 and prior versions.
Exploit / POC
Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
Solution / Fix
Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
Solution:
Vendor updates are available. Contact the vendor for details.
Solution:
Vendor updates are available. Contact the vendor for details.
References
Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
References:
References:
- Important Security Issues (Now Wireless)
- Now SMS/MMS Gateway Homepage (Now Wireless)
- Multiple buffer-overflow in NowSMS v2007.06.27 (Luigi Auriemma
)