Fujitsu Systemcast Wizard Lite PXE Request Remote Buffer Overflow Vulnerability
BID:33342
Info
Fujitsu Systemcast Wizard Lite PXE Request Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 33342 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0270 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2009 12:00AM |
| Updated: | Feb 17 2009 03:48PM |
| Credit: | Ruben Santamarta, Wintercore |
| Vulnerable: |
Fujitsu Systemcast Wizard Lite 2.0a Fujitsu Systemcast Wizard Lite 2.0 Fujitsu Systemcast Wizard Lite 1.9 Fujitsu Systemcast Wizard Lite 1.8a Fujitsu Systemcast Wizard Lite 1.8 Fujitsu Systemcast Wizard Lite 1.7 |
| Not Vulnerable: | |
Discussion
Fujitsu Systemcast Wizard Lite PXE Request Remote Buffer Overflow Vulnerability
Fujitsu Systemcast Wizard Lite is prone to a remote stack-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will compromise the application and the underlying computer. Failed attacks will cause denial-of-service conditions.
Systemcast Wizard Lite 2.0A and prior are vulnerable.
Fujitsu Systemcast Wizard Lite is prone to a remote stack-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will compromise the application and the underlying computer. Failed attacks will cause denial-of-service conditions.
Systemcast Wizard Lite 2.0A and prior are vulnerable.
Exploit / POC
Fujitsu Systemcast Wizard Lite PXE Request Remote Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Fujitsu Systemcast Wizard Lite PXE Request Remote Buffer Overflow Vulnerability
Solution:
Vendor patches are available; please see the references for more information.
Fujitsu Systemcast Wizard Lite 1.8a
Fujitsu Systemcast Wizard Lite 1.7
Fujitsu Systemcast Wizard Lite 2.0a
Fujitsu Systemcast Wizard Lite 1.8
Fujitsu Systemcast Wizard Lite 1.9
Fujitsu Systemcast Wizard Lite 2.0
Solution:
Vendor patches are available; please see the references for more information.
Fujitsu Systemcast Wizard Lite 1.8a
-
Fujitsu TKH0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKH0139.exe
Fujitsu Systemcast Wizard Lite 1.7
-
Fujitsu TKF0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKF0139.exe
Fujitsu Systemcast Wizard Lite 2.0a
-
Fujitsu TKL0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKL0139.exe
Fujitsu Systemcast Wizard Lite 1.8
-
Fujitsu TKG0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKG0139.exe
Fujitsu Systemcast Wizard Lite 1.9
-
Fujitsu TKJ0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKJ0139.exe
Fujitsu Systemcast Wizard Lite 2.0
-
Fujitsu TKK0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKK0139.exe
References
Fujitsu Systemcast Wizard Lite PXE Request Remote Buffer Overflow Vulnerability
References:
References: