InterScan VirusWall Long HELO Buffer Overflow Vulnerability
BID:787
Info
InterScan VirusWall Long HELO Buffer Overflow Vulnerability
| Bugtraq ID: | 787 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1529 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 07 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was posted to Bugtraq by dark spyrit <[email protected]>. |
| Vulnerable: |
Trend Micro InterScan VirusWall 3.3 Trend Micro InterScan VirusWall 3.2.3 |
| Not Vulnerable: | |
Discussion
InterScan VirusWall Long HELO Buffer Overflow Vulnerability
There is a buffer overflow in the HELO command of the smtp gateway which ships as part of the VirusWall product. This buffer overflow could be used to launch arbitrary code on the vulnerable server.
This issue was patched by InterScan, however even with the patch it is possible to cause a DoS of the mail server software by sending between 4075 and 4090 characters.
There is a buffer overflow in the HELO command of the smtp gateway which ships as part of the VirusWall product. This buffer overflow could be used to launch arbitrary code on the vulnerable server.
This issue was patched by InterScan, however even with the patch it is possible to cause a DoS of the mail server software by sending between 4075 and 4090 characters.
Exploit / POC
InterScan VirusWall Long HELO Buffer Overflow Vulnerability
Source and executable for vwxsploit written by dark spyrit <[email protected]>. This exploit will launch a command prompt on a specific port.
ivwdos.pl will crash the VirusWall, even if it has had the original isvw331_patch applied.
Source and executable for vwxsploit written by dark spyrit <[email protected]>. This exploit will launch a command prompt on a specific port.
ivwdos.pl will crash the VirusWall, even if it has had the original isvw331_patch applied.
Solution / Fix
InterScan VirusWall Long HELO Buffer Overflow Vulnerability
Solution:
Trend Micro has issued a patch for this vulnerability. It is available at:
http://download.antivirus.com/ftp/products/patches/isvw331_patch.zip
While it addresses the original issue, it will still allow remote DoS attackes via a 4075-4090 character HELO argument. Trend Micro has released a beta of version 3.4 available at:
http://www.antivirus.com/download/beta_programs/
Customers who do not want to run beta software are advised to contact their Trend Micro support representative for a downgrade to a non-vulnerable previous version.
Solution:
Trend Micro has issued a patch for this vulnerability. It is available at:
http://download.antivirus.com/ftp/products/patches/isvw331_patch.zip
While it addresses the original issue, it will still allow remote DoS attackes via a 4075-4090 character HELO argument. Trend Micro has released a beta of version 3.4 available at:
http://www.antivirus.com/download/beta_programs/
Customers who do not want to run beta software are advised to contact their Trend Micro support representative for a downgrade to a non-vulnerable previous version.
References
InterScan VirusWall Long HELO Buffer Overflow Vulnerability
References:
References: