EMC AutoStart Multiple Buffer Overflow Vulnerabilities
BID:49238
Info
EMC AutoStart Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 49238 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2735 CVE-2011-2735 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2011 12:00AM |
| Updated: | Sep 12 2011 05:10PM |
| Credit: | Sebastian Apelt working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
EMC AutoStart 5.4 EMC AutoStart 5.3 SP3 EMC AutoStart 5.3 SP2 EMC AutoStart 5.3 SP1 EMC AutoStart 5.3 |
| Not Vulnerable: |
EMC AutoStart 5.4.1 |
Discussion
EMC AutoStart Multiple Buffer Overflow Vulnerabilities
EMC AutoStart is prone to multiple buffer-overflow vulnerabilities.
Attackers can leverage these issues to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting these issues will result in the complete compromise of affected computers. Failed exploit attempts may cause denial-of-service condition.
EMC AutoStart is prone to multiple buffer-overflow vulnerabilities.
Attackers can leverage these issues to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting these issues will result in the complete compromise of affected computers. Failed exploit attempts may cause denial-of-service condition.
Exploit / POC
EMC AutoStart Multiple Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
EMC AutoStart Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
EMC AutoStart Multiple Buffer Overflow Vulnerabilities
References:
References:
- AutoStart Homepage (EMC)
- EMC Autostart Domain Name Logging Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)
- EMC Autostart ftAgent Opcode 0x11 Parsing Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)
- EMC Autostart ftAgent Opcode 0x140 Parsing Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)
- ESA-2011-025: Multiple buffer overflow vulnerabilities in EMC AutoStart (
)