Bopup Communication Server Stack-Based Buffer Overflow Vulnerability
BID:43836
Info
Bopup Communication Server Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 43836 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2227 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2009 12:00AM |
| Updated: | Jun 22 2009 12:00AM |
| Credit: | mu-b |
| Vulnerable: |
B Labs Bopup Communication Server 3.2.26.5460 |
| Not Vulnerable: | |
Discussion
Bopup Communication Server Stack-Based Buffer Overflow Vulnerability
The Bopup Communication Server is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected server. Successful attacks will compromise the server and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
Bopup Communication Server 3.2.26.5460 is vulnerable; other versions may also be affected.
The Bopup Communication Server is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected server. Successful attacks will compromise the server and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
Bopup Communication Server 3.2.26.5460 is vulnerable; other versions may also be affected.
Exploit / POC
Bopup Communication Server Stack-Based Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Bopup Communication Server Stack-Based Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Bopup Communication Server Stack-Based Buffer Overflow Vulnerability
References:
References:
- Bopup Communication Server Homepage (B Labs)