H-Sphere Webshell diskusage.cc Buffer Overflow Vulnerability
BID:6540
Info
H-Sphere Webshell diskusage.cc Buffer Overflow Vulnerability
| Bugtraq ID: | 6540 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
Positive Software Corporation H-Sphere 2.3 RC3 |
| Not Vulnerable: |
Positive Software Corporation H-Sphere 2.4 |
Discussion
H-Sphere Webshell diskusage.cc Buffer Overflow Vulnerability
A vulnerability has been discovered in H-Sphere Webshell. The problem occurs due to insufficient bounds checking on user-supplied values.
The vulnerability occurs in the diskusage.cc file and can be triggered by passing the target server a value of excessive length for the 'path' variable.
Successful exploitation of this issue may allow an attacker to overwrite the vulnerable functions instruction pointer to cause the server to execute attacker-supplied code.
A vulnerability has been discovered in H-Sphere Webshell. The problem occurs due to insufficient bounds checking on user-supplied values.
The vulnerability occurs in the diskusage.cc file and can be triggered by passing the target server a value of excessive length for the 'path' variable.
Successful exploitation of this issue may allow an attacker to overwrite the vulnerable functions instruction pointer to cause the server to execute attacker-supplied code.
Exploit / POC
H-Sphere Webshell diskusage.cc Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
H-Sphere Webshell diskusage.cc Buffer Overflow Vulnerability
Solution:
The vendor has confirmed this issue and has released fixes. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
Solution:
The vendor has confirmed this issue and has released fixes. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
-
Positive Software H-Sphere 2.4 Patch
http://www.psoft.net/shiv/U23/u-webshell.tgz
References
H-Sphere Webshell diskusage.cc Buffer Overflow Vulnerability
References:
References:
- Positive Software Homepage (Positive Software)
- Remote root vuln in HSphere WebShell (Carl Livitt
)