BOINC Multiple Vulnerabilities
BID:59542
Info
BOINC Multiple Vulnerabilities
| Bugtraq ID: | 59542 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2013 12:00AM |
| Updated: | Apr 28 2013 12:00AM |
| Credit: | Alyssa Milburn, Michael Vo�?, Gianfranco Costamagna |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
BOINC Multiple Vulnerabilities
BOINC is prone to stack-based buffer-overflow, format-string, and SQL-injection vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
BOINC is prone to stack-based buffer-overflow, format-string, and SQL-injection vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
Exploit / POC
BOINC Multiple Vulnerabilities
An attacker can exploit the SQL-injection issues through readily available tools.
Currently, we are not aware of any exploits for the code-execution issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker can exploit the SQL-injection issues through readily available tools.
Currently, we are not aware of any exploits for the code-execution issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BOINC Multiple Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.