LANDesk Intel QIP Service 'qipsrvr.exe' Buffer Overflow Vulnerability
BID:31193
Info
LANDesk Intel QIP Service 'qipsrvr.exe' Buffer Overflow Vulnerability
| Bugtraq ID: | 31193 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2468 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2008 12:00AM |
| Updated: | Sep 17 2008 05:40PM |
| Credit: | Aaron Portnoy |
| Vulnerable: |
LANDesk Software LANDesk Server Manager 8.8 LANDesk Software LANDesk Server Manager 8.7 LANDesk Software LANDesk Security Suite 8.8 LANDesk Software LANDesk Security Suite 8.7 LANDesk Software LANDesk Management Suite 8.80.1 .1 LANDesk Software LANDesk Management Suite 8.0 LANDesk Software LANDesk Management Suite 7.0 LANDesk Software LANDesk Management Suite 8.8 LANDesk Software LANDesk Management Suite 8.7 |
| Not Vulnerable: | |
Discussion
LANDesk Intel QIP Service 'qipsrvr.exe' Buffer Overflow Vulnerability
LANDesk Intel QIP Service is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Successful exploits may allow an attacker to execute arbitrary code with SYSTEM-level privileges. This will result in a complete compromise of vulnerable computers. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects the following:
LANDesk Management Suite 8.8 and earlier
LANDesk Security Suite 8.8 and earlier
LANDesk Server Manager 8.8 and earlier
LANDesk Intel QIP Service is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Successful exploits may allow an attacker to execute arbitrary code with SYSTEM-level privileges. This will result in a complete compromise of vulnerable computers. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects the following:
LANDesk Management Suite 8.8 and earlier
LANDesk Security Suite 8.8 and earlier
LANDesk Server Manager 8.8 and earlier
Exploit / POC
LANDesk Intel QIP Service 'qipsrvr.exe' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
LANDesk Intel QIP Service 'qipsrvr.exe' Buffer Overflow Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
LANDesk Software LANDesk Management Suite 8.7
LANDesk Software LANDesk Security Suite 8.7
LANDesk Software LANDesk Security Suite 8.8
LANDesk Software LANDesk Server Manager 8.8
LANDesk Software LANDesk Management Suite 8.8
LANDesk Software LANDesk Server Manager 8.7
Solution:
The vendor has released fixes. Please see the references for more information.
LANDesk Software LANDesk Management Suite 8.7
-
LANDesk Software SWD-1620987.5.zip
http://community.landesk.com/downloads/patch/SWD-1620987.5.zip
LANDesk Software LANDesk Security Suite 8.7
-
LANDesk Software SWD-1620987.5.zip
http://community.landesk.com/downloads/patch/SWD-1620987.5.zip
LANDesk Software LANDesk Security Suite 8.8
-
LANDesk Software SWD-1620988.2.zip
http://community.landesk.com/downloads/patch/SWD-1620988.2.zip
LANDesk Software LANDesk Server Manager 8.8
-
LANDesk Software SWD-1620988.2.zip
http://community.landesk.com/downloads/patch/SWD-1620988.2.zip
LANDesk Software LANDesk Management Suite 8.8
-
LANDesk Software SWD-1620988.2.zip
http://community.landesk.com/downloads/patch/SWD-1620988.2.zip
LANDesk Software LANDesk Server Manager 8.7
-
LANDesk Software SWD-1620987.5.zip
http://community.landesk.com/downloads/patch/SWD-1620987.5.zip
References
LANDesk Intel QIP Service 'qipsrvr.exe' Buffer Overflow Vulnerability
References:
References:
- Landesk QIP Server Service Heal Packet Buffer Overflow Vulnerability (TippingPoint)
- TPTI-08-06: Landesk QIP Server Service Heal Packet Buffer Overflow (dvlabs
) - Vulnerability in Intel QIP Service (LANDesk Software)
- Vulnerability Note VU#538011 LANDesk QIP service buffer overflow vulnerability (US-CERT)