Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow Vulnerability
BID:31139
Info
Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow Vulnerability
| Bugtraq ID: | 31139 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2437 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2008 12:00AM |
| Updated: | Sep 12 2008 11:20PM |
| Credit: | Dyon Balding, Secunia Research |
| Vulnerable: |
Trend Micro OfficeScan 8.0 Trend Micro OfficeScan 7.3 Trend Micro OfficeScan 7.0 Trend Micro Client Server Messaging Security 3.6 |
| Not Vulnerable: | |
Discussion
Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow Vulnerability
Trend Micro OfficeScan is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Successful exploits may allow an attacker to execute arbitrary code within the context of the affected application. This may facilitate a complete compromise of vulnerable computers. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects the following:
OfficeScan 7.3 with Patch 4 build 1362
OfficeScan 7.0
OfficeScan 8.0
Client Server Messaging Security versions 3.6, 3.5, 3.0, and 2.0
Trend Micro OfficeScan is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Successful exploits may allow an attacker to execute arbitrary code within the context of the affected application. This may facilitate a complete compromise of vulnerable computers. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects the following:
OfficeScan 7.3 with Patch 4 build 1362
OfficeScan 7.0
OfficeScan 8.0
Client Server Messaging Security versions 3.6, 3.5, 3.0, and 2.0
Exploit / POC
Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Trend Micro OfficeScan 8.0
Trend Micro Client Server Messaging Security 3.6
Trend Micro OfficeScan 7.3
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Trend Micro OfficeScan 8.0
-
Trend Micro OSCE_8.0_SP1_Patch1_Win_EN_CriticalPatch_B3060.exe
Trend Micro OfficeScan 8.0 Service Pack 1 Patch 1
http://www.trendmicro.com/ftp/products/patches/OSCE_8.0_SP1_Patch1_Win _EN_CriticalPatch_B3060.exe -
Trend Micro OSCE_8.0_SP1_Win_EN_CriticalPatch_B2424.exe
Trend Micro OfficeScan 8.0 Service Pack 1.
http://www.trendmicro.com/ftp/products/patches/OSCE_8.0_SP1_Win_EN_Cri ticalPatch_B2424.exe -
Trend Micro OSCE_8.0_Win_EN_CriticalPatch_B1361.exe
Trend Micro OfficeScan 8.0
http://www.trendmicro.com/ftp/products/patches/OSCE_8.0_Win_EN_Critica lPatch_B1361.exe
Trend Micro Client Server Messaging Security 3.6
-
Trend Micro CSM_3.6_OSCE_7.6_Win_EN_CriticalPatch_B1195.exe
Trend Micro Client Server Messaging Security 3.6
http://www.trendmicro.com/ftp/products/patches/CSM_3.6_OSCE_7.6_Win_EN _CriticalPatch_B1195.exe
Trend Micro OfficeScan 7.3
-
Trend Micro OSCE_7.3_Win_EN_CriticalPatch_B1367.exe
Trend Micro OfficeScan 7.3
http://www.trendmicro.com/ftp/products/patches/OSCE_7.3_Win_EN_Critica lPatch_B1367.exe
References
Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow Vulnerability
References:
References:
- Trend Micro OfficeScan Homepage (Trend Micro)
- Trend Micro(TM) Client Server Messaging Security 3.6 Critical Patch - Server Bui (Trend Micro)
- Trend Micro(TM) OfficeScan(TM) 7.3 Critical Patch - Server Build 1367 (Trend Micro)
- Trend Micro(TM) OfficeScan(TM) 8.0 Critical Patch - Server Build 1361 (Trend Micro)
- Trend Micro(TM) OfficeScan(TM) 8.0 Service Pack 1 Critical Patch - Server Build (Trend Micro)
- Trend Micro(TM) OfficeScan(TM) 8.0 Service Pack 1 Patch 1 Critical Patch - Serve (Trend Micro)
- Secunia Research: Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow (Secunia Research
) - Secunia Research: Trend Micro OfficeScan cgiRecvFile.exe Buffer Overflow (Secunia Research)