OpenLink 3.2 Remote Buffer Overflow Vulnerability
BID:720
Info
OpenLink 3.2 Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 720 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 1999 12:00AM |
| Updated: | Oct 15 1999 12:00AM |
| Credit: | First posted to BugTraq by Tymm Twillman <[email protected]> on Oct 15, 1999. |
| Vulnerable: |
OpenLink Software OpenLink 3.2 |
| Not Vulnerable: | |
Discussion
OpenLink 3.2 Remote Buffer Overflow Vulnerability
Both the Unix and WindowsNT versions of OpenLink 3.2 are vulnerable to a remotely exploitable buffer overflow attack. The problem is in their web configuration utility, and is the result of an unchecked strcpy() call. The consequence is the execution of arbitrary code on the target host (running the configuration utility) with the priviliges of the web software.
Both the Unix and WindowsNT versions of OpenLink 3.2 are vulnerable to a remotely exploitable buffer overflow attack. The problem is in their web configuration utility, and is the result of an unchecked strcpy() call. The consequence is the execution of arbitrary code on the target host (running the configuration utility) with the priviliges of the web software.
Exploit / POC
OpenLink 3.2 Remote Buffer Overflow Vulnerability
exploit available
exploit available
Solution / Fix
OpenLink 3.2 Remote Buffer Overflow Vulnerability
Solution:
OpenLink has been notified of this problem and is working on a fix.
Solution:
OpenLink has been notified of this problem and is working on a fix.