H-Sphere Webshell Remote Buffer Overrun Vulnerability
BID:6527
Info
H-Sphere Webshell Remote Buffer Overrun Vulnerability
| Bugtraq ID: | 6527 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
Positive Software Corporation H-Sphere 2.3 RC3 |
| Not Vulnerable: |
Positive Software Corporation H-Sphere 2.4 |
Discussion
H-Sphere Webshell Remote Buffer Overrun Vulnerability
A vulnerability has been discovered in H-Sphere Webshell. During the pre-authentication phase Webshell fails to perform sufficient bounds checking on user-supplied HTTP parameters. As a result, a malicious attacker may be able to trigger a buffer overrun.
Successful exploitation of this issue would allow an attacker to overwrite the vulnerable function's instruction pointer. By causing the program to return to attacker-supplied instructions, it may be possible to execute arbitrary code with the privileges of the target process.
It should be noted that this issue was discovered in H-Sphere 2.3 RC3. It is not yet known whether earlier versions are also vulnerable.
A vulnerability has been discovered in H-Sphere Webshell. During the pre-authentication phase Webshell fails to perform sufficient bounds checking on user-supplied HTTP parameters. As a result, a malicious attacker may be able to trigger a buffer overrun.
Successful exploitation of this issue would allow an attacker to overwrite the vulnerable function's instruction pointer. By causing the program to return to attacker-supplied instructions, it may be possible to execute arbitrary code with the privileges of the target process.
It should be noted that this issue was discovered in H-Sphere 2.3 RC3. It is not yet known whether earlier versions are also vulnerable.
Exploit / POC
H-Sphere Webshell Remote Buffer Overrun Vulnerability
The following exploits have been made available by Carl Livitt:
The following exploits have been made available by Carl Livitt:
Solution / Fix
H-Sphere Webshell Remote Buffer Overrun Vulnerability
Solution:
The vendor has confirmed this issue and has released fixes. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
Solution:
The vendor has confirmed this issue and has released fixes. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
-
Positive Software H-Sphere 2.4 Patch
http://www.psoft.net/shiv/U23/u-webshell.tgz
References
H-Sphere Webshell Remote Buffer Overrun Vulnerability
References:
References:
- Positive Software Homepage (Positive Software)
- Remote root vuln in HSphere WebShell (Carl Livitt
)