Lianja SQL Server 'db_netserver' CVE-2013-3563 Remote Stack Buffer Overflow Vulnerability
BID:60242
Info
Lianja SQL Server 'db_netserver' CVE-2013-3563 Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 60242 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-3563 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2013 12:00AM |
| Updated: | May 22 2013 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Lianja Lianja SQL Server 1.0.0RC5.1 |
| Not Vulnerable: |
Lianja Lianja SQL Server 1.0.0RC5.2 |
Discussion
Lianja SQL Server 'db_netserver' CVE-2013-3563 Remote Stack Buffer Overflow Vulnerability
Lianja SQL Server is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected server. Failed exploit attempts will result in a denial-of-service condition.
Lianja SQL Server is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected server. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Lianja SQL Server 'db_netserver' CVE-2013-3563 Remote Stack Buffer Overflow Vulnerability
The following metasploit exploit code is available:
The following metasploit exploit code is available:
References
Lianja SQL Server 'db_netserver' CVE-2013-3563 Remote Stack Buffer Overflow Vulnerability
References:
References:
- Lianja SQL Server Homepage (Lianja)