Sambar Server Authentication Buffer Overflow Vulnerability
BID:4404
Info
Sambar Server Authentication Buffer Overflow Vulnerability
| Bugtraq ID: | 4404 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2002 12:00AM |
| Updated: | Apr 01 2002 12:00AM |
| Credit: | Discovered by Mark Litchfield <[email protected]>. |
| Vulnerable: |
Sambar Server 5.1 Sambar Server 5.0 beta6 Sambar Server 5.0 beta5 Sambar Server 5.0 beta4 Sambar Server 5.0 beta3 Sambar Server 5.0 beta2 Sambar Server 5.0 beta1 |
| Not Vulnerable: | |
Discussion
Sambar Server Authentication Buffer Overflow Vulnerability
Sambar Server is a multi-threaded web server which will run on Microsoft Windows 9x/ME/NT/2000 operating systems.
A buffer overflow vulnerability has been reported in some versions of Sambar Server. If extremely long strings are sent for the username and password used for authentication, it is possible to overwrite stack memory.
Execution of code with SYSTEM privileges is possible.
Sambar Server is a multi-threaded web server which will run on Microsoft Windows 9x/ME/NT/2000 operating systems.
A buffer overflow vulnerability has been reported in some versions of Sambar Server. If extremely long strings are sent for the username and password used for authentication, it is possible to overwrite stack memory.
Execution of code with SYSTEM privileges is possible.
Exploit / POC
Sambar Server Authentication Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sambar Server Authentication Buffer Overflow Vulnerability
Solution:
A patch is available:
Sambar Server 5.0 beta4
Sambar Server 5.0 beta2
Sambar Server 5.0 beta6
Sambar Server 5.0 beta3
Sambar Server 5.0 beta1
Sambar Server 5.0 beta5
Sambar Server 5.1
Solution:
A patch is available:
Sambar Server 5.0 beta4
-
Sambar sambar51p.exe
http://www.sambarserver.com/download/sambar51p.exe
Sambar Server 5.0 beta2
-
Sambar sambar51p.exe
http://www.sambarserver.com/download/sambar51p.exe
Sambar Server 5.0 beta6
-
Sambar sambar51p.exe
http://www.sambarserver.com/download/sambar51p.exe
Sambar Server 5.0 beta3
-
Sambar sambar51p.exe
http://www.sambarserver.com/download/sambar51p.exe
Sambar Server 5.0 beta1
-
Sambar sambar51p.exe
http://www.sambarserver.com/download/sambar51p.exe
Sambar Server 5.0 beta5
-
Sambar sambar51p.exe
http://www.sambarserver.com/download/sambar51p.exe
Sambar Server 5.1
-
Sambar sambar51p.exe
http://www.sambarserver.com/download/sambar51p.exe
References
Sambar Server Authentication Buffer Overflow Vulnerability
References:
References:
- Sambar Server Product Home Page (Sambar Technologies)