OmniCom winShadow hostname Buffer Overflow Vulnerability
BID:8720
Info
OmniCom winShadow hostname Buffer Overflow Vulnerability
| Bugtraq ID: | 8720 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2003 12:00AM |
| Updated: | Sep 29 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Bahaa Naamneh <[email protected]>. |
| Vulnerable: |
OmniCom winShadow 2.0 |
| Not Vulnerable: | |
Discussion
OmniCom winShadow hostname Buffer Overflow Vulnerability
It has been reported that OmniCom winShadow client is prone to a remote buffer overflow condtion due to insufficient boundary checking. The issue is reported to exist in the process responsible for reading hostnames for the *.osh host files. An attacker may exploit this issue by passing an extra 250 bytes in the hostname parameter of the vulnerable process.
Successful exploitation of this issue may allow an attacker to execute arbitrary code in the context of the client in order to gain unauthorized access to a vulnerable system.
OmniCom winShadow version 2.0 has been reported to be prone to this issue, however other versions may be affected as well.
It has been reported that OmniCom winShadow client is prone to a remote buffer overflow condtion due to insufficient boundary checking. The issue is reported to exist in the process responsible for reading hostnames for the *.osh host files. An attacker may exploit this issue by passing an extra 250 bytes in the hostname parameter of the vulnerable process.
Successful exploitation of this issue may allow an attacker to execute arbitrary code in the context of the client in order to gain unauthorized access to a vulnerable system.
OmniCom winShadow version 2.0 has been reported to be prone to this issue, however other versions may be affected as well.
Exploit / POC
OmniCom winShadow hostname Buffer Overflow Vulnerability
Exploit code has been provided and may downloaded from the following location:
http://www.elitehaven.net/winshadow.zip
Exploit code has been provided and may downloaded from the following location:
http://www.elitehaven.net/winshadow.zip
Solution / Fix
OmniCom winShadow hostname Buffer Overflow Vulnerability
Solution:
The vendor has released a fix for this issue. Please see the reference section to contact the vendor for more information and details on obtaining the fix.
Solution:
The vendor has released a fix for this issue. Please see the reference section to contact the vendor for more information and details on obtaining the fix.