InterSystems Cache 'UtilConfigHome.csp' Remote Stack Buffer Overflow Vulnerability
BID:37177
Info
InterSystems Cache 'UtilConfigHome.csp' Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 37177 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2009 12:00AM |
| Updated: | Oct 22 2010 03:48PM |
| Credit: | Unknown |
| Vulnerable: |
InterSystems Cache 2009.1.2 InterSystems Cache 2009.1.1 InterSystems Cache 2009.1 |
| Not Vulnerable: |
InterSystems Cache 2009.1.3 |
Discussion
InterSystems Cache 'UtilConfigHome.csp' Remote Stack Buffer Overflow Vulnerability
InterSystems Cache is prone to a remote stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the application. Failed exploit attempts will result in denial-of-service conditions.
InterSystems Cache 2009.1 is vulnerable; other versions may also be affected.
InterSystems Cache is prone to a remote stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the application. Failed exploit attempts will result in denial-of-service conditions.
InterSystems Cache 2009.1 is vulnerable; other versions may also be affected.
Exploit / POC
InterSystems Cache 'UtilConfigHome.csp' Remote Stack Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
InterSystems Cache 'UtilConfigHome.csp' Remote Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
InterSystems Cache 'UtilConfigHome.csp' Remote Stack Buffer Overflow Vulnerability
References:
References:
- December 10, 2009 �?? Alert - CSP Gateway Security Exploit (InterSystems)
- InterSystems Caché: Post-relational Database Homepage (InterSystems)