WinSyslog Interactive Syslog Server Long Message Remote Denial Of Service Vulnerability
BID:8821
Info
WinSyslog Interactive Syslog Server Long Message Remote Denial Of Service Vulnerability
| Bugtraq ID: | 8821 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2003 12:00AM |
| Updated: | Oct 14 2003 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
Adiscon WinSyslog 5.0 beta Adiscon WinSyslog 4.21 SP1 Adiscon MonitorWare Agent 1.3 |
| Not Vulnerable: |
Adiscon WinSyslog 5.0 Adiscon WinSyslog 4.2.36 |
Discussion
WinSyslog Interactive Syslog Server Long Message Remote Denial Of Service Vulnerability
WinSyslog is prone to a remotely exploitable denial of service vulnerability. The issue exists in the Interactive Syslog Server specifically. This occurs when the program receives multiple excessive syslog messages via the port it listens on (10514/UDP by default). This is also reported to cause system instability, which is likely due to resource exhaustion.
The issue does not affect the WinSyslog or MonitorWare agent services. This issue affects versions of WinSyslog prior to 2003-09-15. The vendor has released hot fixes for the MonitorWare Agent product, which also includes the vulnerable component.
WinSyslog is prone to a remotely exploitable denial of service vulnerability. The issue exists in the Interactive Syslog Server specifically. This occurs when the program receives multiple excessive syslog messages via the port it listens on (10514/UDP by default). This is also reported to cause system instability, which is likely due to resource exhaustion.
The issue does not affect the WinSyslog or MonitorWare agent services. This issue affects versions of WinSyslog prior to 2003-09-15. The vendor has released hot fixes for the MonitorWare Agent product, which also includes the vulnerable component.
Exploit / POC
WinSyslog Interactive Syslog Server Long Message Remote Denial Of Service Vulnerability
The following exploit script was submitted:
The following exploit script was submitted:
Solution / Fix
WinSyslog Interactive Syslog Server Long Message Remote Denial Of Service Vulnerability
Solution:
The vendor has addressed this in WinSyslog versions 5.0 final and 4.2.36. Hot fixes are also available.
Adiscon MonitorWare Agent 1.3
Adiscon WinSyslog 4.21 SP1
Adiscon WinSyslog 5.0 beta
Solution:
The vendor has addressed this in WinSyslog versions 5.0 final and 4.2.36. Hot fixes are also available.
Adiscon MonitorWare Agent 1.3
-
Adiscon MWAgent-hotfix-2003-09-15.zip
http://www.adiscon.org/download/MWAgent-hotfix-2003-09-15.zip
Adiscon WinSyslog 4.21 SP1
-
Adiscon WinSyslog-hotfix-2003-09-15.zip
http://www.adiscon.org/download/WinSyslog-hotfix-2003-09-15.zip
Adiscon WinSyslog 5.0 beta
-
Adiscon WinSyslog-hotfix-2003-09-15.zip
http://www.adiscon.org/download/WinSyslog-hotfix-2003-09-15.zip
References
WinSyslog Interactive Syslog Server Long Message Remote Denial Of Service Vulnerability
References:
References:
- Potential DoS in Interactive Syslog Server (Adiscon)
- WinSyslog Homepage (WinSyslog)