HP CIFSLogin Buffer Overflow Vulnerability
BID:5088
Info
HP CIFSLogin Buffer Overflow Vulnerability
| Bugtraq ID: | 5088 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0991 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 24 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Credited to Alex Hernandez <[email protected]>. |
| Vulnerable: |
HP CIFS/9000 Server A.01.06 HP CIFS/9000 Server A.01.05 |
| Not Vulnerable: |
HP CIFS/9000 Server A.01.07 |
Discussion
HP CIFSLogin Buffer Overflow Vulnerability
A vulnerability has been reported in the /opt/cifsclient/bin/cifslogin utility distributed with CIFS/9000. The utility is prone to several buffer overflow conditions and may lead to root compromise.
The vulnerability occurs due to the lack of bounds checking when accepting user input for various commandline options. Specifically, the utility fails to check for excessively long arguments to the following commandline options: '-U', '-D', '-P', '-S', '-N', and '-u'.
A vulnerability has been reported in the /opt/cifsclient/bin/cifslogin utility distributed with CIFS/9000. The utility is prone to several buffer overflow conditions and may lead to root compromise.
The vulnerability occurs due to the lack of bounds checking when accepting user input for various commandline options. Specifically, the utility fails to check for excessively long arguments to the following commandline options: '-U', '-D', '-P', '-S', '-N', and '-u'.
Exploit / POC
HP CIFSLogin Buffer Overflow Vulnerability
Exploit code is available:
Exploit code is available:
Solution / Fix
HP CIFSLogin Buffer Overflow Vulnerability
Solution:
HP is aware of the vulnerability and has strongly suggested applying the following patches:
Upgrade to A.01.06, and then install patch PHNE_24164 for
HP-UX release 11.00 or 11.11.
CIFS/9000 Client version A.01.07 includes this fix.
HP CIFS/9000 Server A.01.05
HP CIFS/9000 Server A.01.06
Solution:
HP is aware of the vulnerability and has strongly suggested applying the following patches:
Upgrade to A.01.06, and then install patch PHNE_24164 for
HP-UX release 11.00 or 11.11.
CIFS/9000 Client version A.01.07 includes this fix.
HP CIFS/9000 Server A.01.05
-
HP Product B8724AA
CIFS/9000 Client version A.01.07
http://www.software.hp.com
HP CIFS/9000 Server A.01.06
-
HP PHNE_24164
http://itrc.hp.com -
HP Product B8724AA
CIFS/9000 Client version A.01.07
http://www.software.hp.com