Mathematica License Manager Arbitrary License Retrieval Vulnerability
BID:3118
Info
Mathematica License Manager Arbitrary License Retrieval Vulnerability
| Bugtraq ID: | 3118 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2001-1058 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced to Bugtraq by Pinwheel <[email protected]> on July 30, 2001. |
| Vulnerable: |
Wolfram Research Mathematica 4.1 Wolfram Research Mathematica 4.0 |
| Not Vulnerable: | |
Discussion
Mathematica License Manager Arbitrary License Retrieval Vulnerability
Mathematica is a mathematical computation software package distributed and maintained by Wolfram Research.
It is possible for remote users to gain arbitrary access to Mathematica licenses. Depending upon the implementation of access control, a user may be able to request a license using a spoof request. Upon receiving the request, of the client name in the spoofed request is authorized a license, it will be sent.
This could result in the theft of Mathematica licenses, and potentially a denial of service from all licenses being in use.
Mathematica is a mathematical computation software package distributed and maintained by Wolfram Research.
It is possible for remote users to gain arbitrary access to Mathematica licenses. Depending upon the implementation of access control, a user may be able to request a license using a spoof request. Upon receiving the request, of the client name in the spoofed request is authorized a license, it will be sent.
This could result in the theft of Mathematica licenses, and potentially a denial of service from all licenses being in use.
Exploit / POC
Mathematica License Manager Arbitrary License Retrieval Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mathematica License Manager Arbitrary License Retrieval Vulnerability
References:
References: