Microsoft Commerce Server OWC Package Installer Buffer Overflow Vulnerability
BID:5108
Info
Microsoft Commerce Server OWC Package Installer Buffer Overflow Vulnerability
| Bugtraq ID: | 5108 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2002 12:00AM |
| Updated: | Jun 26 2002 12:00AM |
| Credit: | Microsoft has credited Mark Litchfield of Next Generation Security Software Ltd. for reporting this vulnerability. |
| Vulnerable: |
Microsoft Commerce Server 2000 SP2 Microsoft Commerce Server 2000 SP1 Microsoft Commerce Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Commerce Server OWC Package Installer Buffer Overflow Vulnerability
Microsoft Commerce Server is a web server products for building, deploying, and analyzing e-commerce sites.
The OWC package installer implemented by Commerce Server is susceptible to a buffer overflow vulnerability. In the event that an authenticated attacker were to supply specially crafted malformed data to the OWC package installer, a denial of service attack or execution of arbitrary code may result depending on the data entered. Exploitation would occur in the LocalSystem security context. Only Microsoft Commerce Server 2000 is susceptible to this vulnerability.
Microsoft Commerce Server is a web server products for building, deploying, and analyzing e-commerce sites.
The OWC package installer implemented by Commerce Server is susceptible to a buffer overflow vulnerability. In the event that an authenticated attacker were to supply specially crafted malformed data to the OWC package installer, a denial of service attack or execution of arbitrary code may result depending on the data entered. Exploitation would occur in the LocalSystem security context. Only Microsoft Commerce Server 2000 is susceptible to this vulnerability.
Solution / Fix
Microsoft Commerce Server OWC Package Installer Buffer Overflow Vulnerability
Solution:
The patch provided by Microsoft is meant to prevent remote execution of the OWC package installer. It does not fix the buffer overflow vulnerability.
Microsoft has released a patch to address this vulnerability:
Microsoft Commerce Server 2000 SP2
Microsoft Commerce Server 2000
Solution:
The patch provided by Microsoft is meant to prevent remote execution of the OWC package installer. It does not fix the buffer overflow vulnerability.
Microsoft has released a patch to address this vulnerability:
Microsoft Commerce Server 2000 SP2
-
Microsoft Q322273
http://download.microsoft.com/download/comserver/Patch/1.1/NT5/EN-US/Q 322273_EN.EXE
Microsoft Commerce Server 2000
References
Microsoft Commerce Server OWC Package Installer Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-033 (Microsoft)