Hitachi Multiple Products Image File Parsing Buffer Overflow Vulnerability
BID:38000
Info
Hitachi Multiple Products Image File Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 38000 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2010 12:00AM |
| Updated: | Jan 29 2010 12:00AM |
| Credit: | The issue is reported by the vendor. |
| Vulnerable: |
Hitachi uCosminexus/OpenTP1 Web Front-end Set 0 Hitachi uCosminexus Service Platform 8 Hitachi uCosminexus Service Platform 7 Hitachi uCosminexus Service Platform 6.7 Hitachi uCosminexus Service Architect 8 Hitachi uCosminexus Service Architect 7 Hitachi uCosminexus Service Architect 6.7 Hitachi uCosminexus Portal Framework Entry Set 0 Hitachi uCosminexus Operator 8 Hitachi uCosminexus Operator 7 Hitachi uCosminexus Operator 6.7 Hitachi uCosminexus Navigation Platform Authoring License 0 Hitachi uCosminexus Navigation Platform - User License 0 Hitachi uCosminexus Navigation Platform 0 Hitachi uCosminexus Navigation Developer 0 Hitachi uCosminexus Developer Standard 8 Hitachi uCosminexus Developer Standard 7 Hitachi uCosminexus Developer Standard 6.7 Hitachi uCosminexus Developer Standard 6 Hitachi uCosminexus Developer Professional 8 Hitachi uCosminexus Developer Professional 7 Hitachi uCosminexus Developer Professional 6.7 Hitachi uCosminexus Developer Professional 6 Hitachi uCosminexus Developer Light 8 Hitachi uCosminexus Developer Light 7 Hitachi uCosminexus Developer Light 6.7 Hitachi uCosminexus Collaboration Server 0 Hitachi uCosminexus Client 8 Hitachi uCosminexus Client 7 Hitachi uCosminexus Client 6.7 Hitachi uCosminexus Application Server Standard Version 6 Hitachi uCosminexus Application Server Standard 8 Hitachi uCosminexus Application Server Standard 7 Hitachi uCosminexus Application Server Standard 6.7 Hitachi uCosminexus Application Server Enterprise Version 6 Hitachi uCosminexus Application Server Enterprise 8 Hitachi uCosminexus Application Server Enterprise 7 Hitachi uCosminexus Application Server Enterprise 6.7 Hitachi Groupmax Collaboration Server 0 Hitachi Electronic Form Workflow Standard Set 0 Hitachi Electronic Form Workflow Set 0 Hitachi Electronic Form Workflow Professional Set 0 Hitachi Electronic Form Workflow Professional Library Set 0 Hitachi Electronic Form Workflow Developer Set 0 Hitachi Electronic Form Workflow Developer Client Set 0 Hitachi Cosminexus Studio Web Edition 4 Hitachi Cosminexus Studio Standard Edition 4 Hitachi Cosminexus Studio 5 Hitachi Cosminexus Server Web Edition 4 Hitachi Cosminexus Server Standard Edition 4 Hitachi Cosminexus Developer Light 6 Hitachi Cosminexus Developer 5 Hitachi Cosminexus Client 6 Hitachi Cosminexus Application Server 5.0 |
| Not Vulnerable: | |
Discussion
Hitachi Multiple Products Image File Parsing Buffer Overflow Vulnerability
Multiple Hitachi products, including Cosminexus, Processing Kit for XML, and Hitachi Developer's Kit for Java, are prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Multiple Hitachi products, including Cosminexus, Processing Kit for XML, and Hitachi Developer's Kit for Java, are prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Hitachi Multiple Products Image File Parsing Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Hitachi Multiple Products Image File Parsing Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Hitachi Multiple Products Image File Parsing Buffer Overflow Vulnerability
References:
References:
- Hitachi Homepage (Hitachi)
- Hitachi Products Homepage (Hitachi)
- Buffer Overflow Vulnerability in Cosminexus, Processing Kit for XML, and Hitachi (Hitachi)