Netwin NWAuth Buffer Overflow Vulnerabilities
BID:3077
Info
Netwin NWAuth Buffer Overflow Vulnerabilities
| Bugtraq ID: | 3077 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1355 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Reported to Bugtraq by ByteRage <[email protected]> on July 20, 2001. |
| Vulnerable: |
NetWin SurgeFTP 2.0 b NetWin SurgeFTP 2.0 a NetWin SurgeFTP 1.0 b NetWin DMail 2.8 i NetWin DMail 2.8 h NetWin DMail 2.8 g NetWin DMail 2.8 f NetWin DMail 2.8 e NetWin DMail 2.7 r NetWin DMail 2.7 q NetWin DMail 2.7 NetWin DMail 2.5 d |
| Not Vulnerable: | |
Discussion
Netwin NWAuth Buffer Overflow Vulnerabilities
The Netwin Authentication module, or NWAuth, is an external authentication module used by several Netwin products.
Numerous boundary condition errors exist in NWAuth. It may be possible for an attacker to exploit these buffer overflows to execute arbitrary code through a service that uses NWAuth. This could lead to full system compromise.
The Netwin Authentication module, or NWAuth, is an external authentication module used by several Netwin products.
Numerous boundary condition errors exist in NWAuth. It may be possible for an attacker to exploit these buffer overflows to execute arbitrary code through a service that uses NWAuth. This could lead to full system compromise.
Solution / Fix
Netwin NWAuth Buffer Overflow Vulnerabilities
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.