Sybase M-Business Anywhere 'agd.exe' 'encodeUsername()' Function Remote Code Execution Vulnerability
BID:47776
Info
Sybase M-Business Anywhere 'agd.exe' 'encodeUsername()' Function Remote Code Execution Vulnerability
| Bugtraq ID: | 47776 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2011 12:00AM |
| Updated: | May 09 2011 12:00AM |
| Credit: | AbdulAziz Hariri |
| Vulnerable: |
Sybase M-Business Anywhere 7.0 Sybase M-Business Anywhere 6.7 |
| Not Vulnerable: | |
Discussion
Sybase M-Business Anywhere 'agd.exe' 'encodeUsername()' Function Remote Code Execution Vulnerability
Sybase M-Business Anywhere is prone to a remote code-execution vulnerability because it fails to properly validate user-supplied input, which can lead to a heap-based buffer overflow.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition. Successful exploits will completely compromise an affected computer.
M-Business Anywhere 6.7 and 7.0 are vulnerable.
Sybase M-Business Anywhere is prone to a remote code-execution vulnerability because it fails to properly validate user-supplied input, which can lead to a heap-based buffer overflow.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition. Successful exploits will completely compromise an affected computer.
M-Business Anywhere 6.7 and 7.0 are vulnerable.
Exploit / POC
Sybase M-Business Anywhere 'agd.exe' 'encodeUsername()' Function Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sybase M-Business Anywhere 'agd.exe' 'encodeUsername()' Function Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Sybase M-Business Anywhere 'agd.exe' 'encodeUsername()' Function Remote Code Execution Vulnerability
References:
References:
- M-Business Anywhere Homepage (Sybase)
- ZDI-11-155: Sybase M-Business Anywhere Server agd.exe encodeUsername Remote Cod (ZDI Disclosures
) - Urgent from Sybase: Possible security vulnerabilities in M-Business Anywhere 6.7 (Sybase)
- ZDI-11-155 Sybase M-Business Anywhere Server agd.exe encodeUsername Remote Code (Zero Day Initiative)