Attachmate Reflection DLL Loading Arbitrary Code Execution Vulnerability
BID:50496
Info
Attachmate Reflection DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 50496 |
| Class: | Design Error |
| CVE: |
CVE-2011-5157 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2011 12:00AM |
| Updated: | Sep 06 2012 10:50PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Attachmate Reflection X 14.0.5 Attachmate Reflection X 14.1 Attachmate Reflection X 14.0 Attachmate Reflection for UNIX and OpenVMS 14.0.5 Attachmate Reflection for IBM 14.0.5 Attachmate Reflection for HP 14.0.5 Attachmate Reflection 14.1 Attachmate Reflection 14.0 SP1 Attachmate Reflection 14.0 |
| Not Vulnerable: |
Attachmate Reflection 14.1 SP1 |
Discussion
Attachmate Reflection DLL Loading Arbitrary Code Execution Vulnerability
Attachmate Reflection is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to open a file (using the vulnerable application) from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Attachmate Reflection is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to open a file (using the vulnerable application) from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Exploit / POC
Attachmate Reflection DLL Loading Arbitrary Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Attachmate Reflection DLL Loading Arbitrary Code Execution Vulnerability
Solution:
The vendor released an advisory and fixes. Please see the references for details.
Solution:
The vendor released an advisory and fixes. Please see the references for details.
References
Attachmate Reflection DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Attachmate Homepage (Attachmate)
- Security Updates and Reflection (Attachmate)