WebC.CGI Environment Variable Buffer Overflow Vulnerability
BID:7277
Info
WebC.CGI Environment Variable Buffer Overflow Vulnerability
| Bugtraq ID: | 7277 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 03 2003 12:00AM |
| Updated: | Apr 03 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
AutomatedShops WebC 5.0 10 AutomatedShops WebC 5.0 05 AutomatedShops WebC 5.0 AutomatedShops WebC 2.0 11 |
| Not Vulnerable: |
AutomatedShops WebC 5.0 20 |
Discussion
WebC.CGI Environment Variable Buffer Overflow Vulnerability
It has been reported that the WebC.cgi application is prone to a buffer overflow condition that may be triggered under specific configurations.
If debugging is enabled, when the User ID is changed during runtime, the WebC.cgi application will parse the environment and save the contents to a locally stored file.
If a malicious environment variable of excessive length is parsed by the vulnerable WebC.cgi application the bounds of a local buffer may be overflowed and adjacent memory corrupted by attacker supplied values.
Although unconfirmed code execution may be possible.
It has been reported that the WebC.cgi application is prone to a buffer overflow condition that may be triggered under specific configurations.
If debugging is enabled, when the User ID is changed during runtime, the WebC.cgi application will parse the environment and save the contents to a locally stored file.
If a malicious environment variable of excessive length is parsed by the vulnerable WebC.cgi application the bounds of a local buffer may be overflowed and adjacent memory corrupted by attacker supplied values.
Although unconfirmed code execution may be possible.
Exploit / POC
WebC.CGI Environment Variable Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WebC.CGI Environment Variable Buffer Overflow Vulnerability
Solution:
The vendor has released a new version to address this issue:
AutomatedShops WebC 2.0 11
AutomatedShops WebC 5.0 05
AutomatedShops WebC 5.0 10
AutomatedShops WebC 5.0
Solution:
The vendor has released a new version to address this issue:
AutomatedShops WebC 2.0 11
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
AutomatedShops WebC 5.0 05
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
AutomatedShops WebC 5.0 10
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
AutomatedShops WebC 5.0
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
References
WebC.CGI Environment Variable Buffer Overflow Vulnerability
References:
References:
- AutomatedShops Homepage (AutomatedShops)
- Multiple vulnerabilities in AutomatedShops WebC shopping cart (Carl Livitt
)