RETIRED: Amlib NetOPAC 'webquery.dll' Stack Remote Buffer Overflow Vulnerability
BID:42293
Info
RETIRED: Amlib NetOPAC 'webquery.dll' Stack Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 42293 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2010 12:00AM |
| Updated: | Oct 25 2010 04:08PM |
| Credit: | Patrick Webster |
| Vulnerable: |
Amlib NetOPAC 5.2.0.4 |
| Not Vulnerable: | |
Discussion
RETIRED: Amlib NetOPAC 'webquery.dll' Stack Remote Buffer Overflow Vulnerability
Amlib NetOPAC is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it to an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of an application that uses the affected library. Failed exploit attempts will result in a denial-of-service condition.
Amlib NetOPAC 5.2.0.4 is vulnerable; other versions may also be affected.
RETIRED: This BID is retired because it is a duplicate of the issue described in BID 42152 (Amlib Library Management System 'webquery.dll' Stack Buffer Overflow Vulnerability).
Amlib NetOPAC is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it to an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of an application that uses the affected library. Failed exploit attempts will result in a denial-of-service condition.
Amlib NetOPAC 5.2.0.4 is vulnerable; other versions may also be affected.
RETIRED: This BID is retired because it is a duplicate of the issue described in BID 42152 (Amlib Library Management System 'webquery.dll' Stack Buffer Overflow Vulnerability).
Exploit / POC
RETIRED: Amlib NetOPAC 'webquery.dll' Stack Remote Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
RETIRED: Amlib NetOPAC 'webquery.dll' Stack Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Amlib NetOPAC 'webquery.dll' Stack Remote Buffer Overflow Vulnerability
References:
References:
- Amlib Library Software: NetOPAC (Amlib)
- Amlibweb NetOpacs webquery.dll Stack Overflow (Rapid7 LLC)