H-Sphere Webshell flist() Buffer Overflow Vulnerability
BID:6538
Info
H-Sphere Webshell flist() Buffer Overflow Vulnerability
| Bugtraq ID: | 6538 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | The discovery of this vulnerability is credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
Positive Software Corporation H-Sphere 2.3 RC3 |
| Not Vulnerable: |
Positive Software Corporation H-Sphere 2.4 |
Discussion
H-Sphere Webshell flist() Buffer Overflow Vulnerability
A remotely exploitable vulnerability has been discovered in H-Sphere. A buffer overflow exists in the flist() function used by the WebShell component. It may be possible for an attacker to exploit this vulnerability by supplying a directory name of excessive length.
A remotely exploitable vulnerability has been discovered in H-Sphere. A buffer overflow exists in the flist() function used by the WebShell component. It may be possible for an attacker to exploit this vulnerability by supplying a directory name of excessive length.
Exploit / POC
H-Sphere Webshell flist() Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
H-Sphere Webshell flist() Buffer Overflow Vulnerability
Solution:
The vendor has addressed this issue in the latest released of H-Sphere. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
Solution:
The vendor has addressed this issue in the latest released of H-Sphere. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
-
Positive Software H-Sphere 2.4 Patch
http://www.psoft.net/shiv/U23/u-webshell.tgz
References
H-Sphere Webshell flist() Buffer Overflow Vulnerability
References:
References:
- Positive Software Homepage (Positive Software)
- Remote root vuln in HSphere WebShell (Carl Livitt
)