SyncBack Profile File Remote Buffer Overflow Vulnerability
BID:40311
Info
SyncBack Profile File Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 40311 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1688 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Lincoln, Corelan Team |
| Vulnerable: |
2BrightSparks Pte Ltd SyncBack 3.2.20 |
| Not Vulnerable: |
2BrightSparks Pte Ltd SyncBack 3.2.21 |
Discussion
SyncBack Profile File Remote Buffer Overflow Vulnerability
SyncBack is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
SyncBack 3.2.20 is vulnerable; other versions may also be affected.
SyncBack is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
SyncBack 3.2.20 is vulnerable; other versions may also be affected.
Exploit / POC
SyncBack Profile File Remote Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
SyncBack Profile File Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
SyncBack Profile File Remote Buffer Overflow Vulnerability
References:
References:
- SyncBack V3.2.21 (2BrightSparks)
- Vendor Homepage (2BrightSparks)