Toshiba ConfigFree 'CF7' File Multiple Stack Based Buffer Overflow Vulnerabilities
BID:55644
CVE-2012-4980 |Info
Toshiba ConfigFree 'CF7' File Multiple Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 55644 |
| Class: | Design Error |
| CVE: |
CVE-2012-4980 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2012 12:00AM |
| Updated: | Sep 21 2012 12:00AM |
| Credit: | Joseph Sheridan |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Toshiba ConfigFree 'CF7' File Multiple Stack Based Buffer Overflow Vulnerabilities
Toshiba ConfigFree is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary-checks on user-supplied data.
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Successful exploits may compromise the application and the underlying computer. Failed exploit attempts will result in a denial-of-service condition.
Toshiba ConfigFree 8.0.38 is vulnerable; other version may also be affected.
Toshiba ConfigFree is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary-checks on user-supplied data.
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Successful exploits may compromise the application and the underlying computer. Failed exploit attempts will result in a denial-of-service condition.
Toshiba ConfigFree 8.0.38 is vulnerable; other version may also be affected.
Exploit / POC
Toshiba ConfigFree 'CF7' File Multiple Stack Based Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Toshiba ConfigFree 'CF7' File Multiple Stack Based Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Toshiba ConfigFree 'CF7' File Multiple Stack Based Buffer Overflow Vulnerabilities
References:
References:
- Toshiba ConfigFree CF7 File Stack Buffer Overflow (Comment Field (Joseph Sheridan)
- Toshiba ConfigFree CF7 File Stack Buffer Overflow (ProfileName) (Reaction Information Security Ltd)
- Toshiba Homepage (Toshiba)