TalentSoft Web+ Webpsvc Buffer Overflow Vulnerability
BID:4233
Info
TalentSoft Web+ Webpsvc Buffer Overflow Vulnerability
| Bugtraq ID: | 4233 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0449 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This issue was reported in a NGSSoftware Insight Security Research Advisory. |
| Vulnerable: |
TalentSoft Web+ Server 5.0 TalentSoft Web+ Server 4.6 |
| Not Vulnerable: | |
Discussion
TalentSoft Web+ Webpsvc Buffer Overflow Vulnerability
TalentSoft Web+ is an environment for developing web-based client/server applications. It will run on Microsoft Windows 9x/NT/2000 operating systems.
The Web+ executable does not perform sufficient bounds checking on strings that are passed to services. In particular, an excessively long URL may cause stack variables to be overwritten, potentially resulting in the execution of attacker-supplied instructions. At the very least, this may cause a denial of service to the Web+ server.
Since the services in question run with SYSTEM privileges, successful exploitation resulting in arbitrary code execution will enable a remote attacker to fully compromise a host running the vulnerable software.
TalentSoft Web+ is an environment for developing web-based client/server applications. It will run on Microsoft Windows 9x/NT/2000 operating systems.
The Web+ executable does not perform sufficient bounds checking on strings that are passed to services. In particular, an excessively long URL may cause stack variables to be overwritten, potentially resulting in the execution of attacker-supplied instructions. At the very least, this may cause a denial of service to the Web+ server.
Since the services in question run with SYSTEM privileges, successful exploitation resulting in arbitrary code execution will enable a remote attacker to fully compromise a host running the vulnerable software.
Exploit / POC
TalentSoft Web+ Webpsvc Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
TalentSoft Web+ Webpsvc Buffer Overflow Vulnerability
Solution:
Patches are available.
TalentSoft Web+ Server 4.6
TalentSoft Web+ Server 5.0
Solution:
Patches are available.
TalentSoft Web+ Server 4.6
-
TalentSoft webplus_46_security_patch2.exe
ftp://ftp.talentsoft.com/download/webplus/windows/webplus_46_security_ patch2.exe
TalentSoft Web+ Server 5.0
-
TalentSoft webplus_50_security_patch.exe
ftp://ftp.talentsoft.com/download/webplus/windows/webplus_50_security_ patch.exe
References
TalentSoft Web+ Webpsvc Buffer Overflow Vulnerability
References:
References:
- Buffer Overflow (TalentSoft)
- TalentSoft Homepage (TalentSoft)