ActFax 'Import Users from File' Function Remote Stack Based Buffer Overflow Vulnerability
BID:55457
Info
ActFax 'Import Users from File' Function Remote Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 55457 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2012 12:00AM |
| Updated: | Sep 07 2012 12:00AM |
| Credit: | Craig Freyman, juan vazquez, and Brandon Perry |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ActFax 'Import Users from File' Function Remote Stack Based Buffer Overflow Vulnerability
ActFax (ActiveFax Server) is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
ActFax (ActiveFax Server) is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
ActFax 'Import Users from File' Function Remote Stack Based Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
ActFax 'Import Users from File' Function Remote Stack Based Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ActFax 'Import Users from File' Function Remote Stack Based Buffer Overflow Vulnerability
References:
References:
- Actfax Homepage (Actfax)