SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vulnerability
BID:28183
Info
SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vulnerability
| Bugtraq ID: | 28183 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0307 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2008 12:00AM |
| Updated: | Mar 12 2008 05:21PM |
| Credit: | The discoverer of this issue wishes to remain anonymous. |
| Vulnerable: |
SAP MaxDB 7.6.0.37 |
| Not Vulnerable: | |
Discussion
SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vulnerability
SAP MaxDB is prone to a heap-based memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Successfully exploiting this issue will compromise the affected application and possibly the underlying computer.
This issue affects MaxDB 7.6.0.37 running on the Linux operating system. Other versions running on different platforms may also be affected.
SAP MaxDB is prone to a heap-based memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Successfully exploiting this issue will compromise the affected application and possibly the underlying computer.
This issue affects MaxDB 7.6.0.37 running on the Linux operating system. Other versions running on different platforms may also be affected.
Exploit / POC
SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vulnerability
Solution:
The vendor released updates to address this issue. Please see SAP note 1140135 for information on how to obtain and apply these updates.
Solution:
The vendor released updates to address this issue. Please see SAP note 1140135 for information on how to obtain and apply these updates.
References
SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vulnerability
References:
References:
- SAP MaxDB Homepage (SAP)
- SAP MaxDB Signedness Error Heap Corruption Vulnerability (iDefense Labs)
- iDefense Security Advisory 03.10.08: SAP MaxDB Signedness Error Heap Memory Corr (iDefense Labs
)