Qbik WinGate Buffer Overflow DoS Vulnerability
BID:509
Info
Qbik WinGate Buffer Overflow DoS Vulnerability
| Bugtraq ID: | 509 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 22 1999 12:00AM |
| Updated: | Feb 22 1999 12:00AM |
| Credit: | eEye Security Advisory AD02221999 released February 22 1999. |
| Vulnerable: |
Qbik WinGate Standard 4.0.1 Qbik WinGate Pro 4.0.1 Qbik WinGate 3.0 |
| Not Vulnerable: | |
Discussion
Qbik WinGate Buffer Overflow DoS Vulnerability
WinGate's Winsock redirector service is susceptible to a buffer overflow vilnerability that will crash all WinGate services.
WinGate's Winsock redirector service is susceptible to a buffer overflow vilnerability that will crash all WinGate services.
Exploit / POC
Qbik WinGate Buffer Overflow DoS Vulnerability
Telnet to the target machine, port 2080
Send 1079 characters
Prizm <[email protected]> has provided the following exploit - wingate.py
Blue Panda <[email protected]> has provided the following exploit for version 4.0.1 - wgate401.pl
Telnet to the target machine, port 2080
Send 1079 characters
Prizm <[email protected]> has provided the following exploit - wingate.py
Blue Panda <[email protected]> has provided the following exploit for version 4.0.1 - wgate401.pl
Solution / Fix
Qbik WinGate Buffer Overflow DoS Vulnerability
Solution:
The following release of Wingate (version 4.1) will not be susceptible to this vulnerability. The beta version is available for download at the following location:
http://wingate.deerfield.com/beta
Solution:
The following release of Wingate (version 4.1) will not be susceptible to this vulnerability. The beta version is available for download at the following location:
http://wingate.deerfield.com/beta
References
Qbik WinGate Buffer Overflow DoS Vulnerability
References:
References:
- eEye Digital Security Team Home Page (eEye)
- WinGate Product Homepage (Qbik)