SafeNet SoftRemote Policy File Handling Remote Buffer Overflow Vulnerabilities
BID:36907
Info
SafeNet SoftRemote Policy File Handling Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 36907 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2009 12:00AM |
| Updated: | Dec 02 2009 06:54PM |
| Credit: | Brett Gervasoni |
| Vulnerable: |
SafeNet SoftRemote 10.8.5 build 2 SafeNet SoftRemote 10.3.5 build 6 |
| Not Vulnerable: | |
Discussion
SafeNet SoftRemote Policy File Handling Remote Buffer Overflow Vulnerabilities
SafeNet SoftRemote is prone to remote buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit these issues to execute arbitrary code with SYSTEM privileges. Failed attacks will cause denial-of-service conditions
The following are vulnerable:
SoftRemote 10.8.5 build 2
SoftRemote 10.3.5 build 6
Other versions may also be affected.
SafeNet SoftRemote is prone to remote buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit these issues to execute arbitrary code with SYSTEM privileges. Failed attacks will cause denial-of-service conditions
The following are vulnerable:
SoftRemote 10.8.5 build 2
SoftRemote 10.3.5 build 6
Other versions may also be affected.
Exploit / POC
SafeNet SoftRemote Policy File Handling Remote Buffer Overflow Vulnerabilities
The researchers responsible for discovering these issues have developed a proof of concept but it is not publicly available.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The researchers responsible for discovering these issues have developed a proof of concept but it is not publicly available.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
SafeNet SoftRemote Policy File Handling Remote Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SafeNet SoftRemote Policy File Handling Remote Buffer Overflow Vulnerabilities
References:
References:
- SafeNet SoftRemote Local Buffer Overflow (Sense of Security)
- SoftRemote Homepage (SafeNet)