Intellicom 'NetBiterConfig.exe' 'Hostname' Data Remote Stack Buffer Overflow Vulnerability
BID:37325
Info
Intellicom 'NetBiterConfig.exe' 'Hostname' Data Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 37325 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-4462 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Mar 25 2010 04:42PM |
| Credit: | Ruben Santamarta |
| Vulnerable: |
IntelliCom Innovation NetBiterConfig.exe 1.3 |
| Not Vulnerable: |
IntelliCom Innovation NetBiterConfig.exe 1.3.1 |
Discussion
Intellicom 'NetBiterConfig.exe' 'Hostname' Data Remote Stack Buffer Overflow Vulnerability
Intellicom 'NetBiterConfig.exe' is prone to a remote stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Intellicom 'NetBiterConfig.exe' is prone to a remote stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Intellicom 'NetBiterConfig.exe' 'Hostname' Data Remote Stack Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Intellicom 'NetBiterConfig.exe' 'Hostname' Data Remote Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Intellicom 'NetBiterConfig.exe' 'Hostname' Data Remote Stack Buffer Overflow Vulnerability
References:
References:
- Important information January 14, 2010 (Intellicom)
- IntelliCom Innovation Homepage (IntelliCom Innovation)
- Reverse Mode - Exposing HMS HICP Protocol + 0Day 'light' + SCADA_SHODAN (Ruben Santamarta)
- Exposing HMS HICP Protocol + Intellicom NetBiterConfig.exe Remote Buffer Overflo (Reversemode
) - Vulnerability Note VU#181737 IntelliCom NetBiter Config HICP hostname buffer ove (US-CERT)