Fujitsu tsworks Attachment Expansion Buffer Overflow Vulnerability
BID:9017
Info
Fujitsu tsworks Attachment Expansion Buffer Overflow Vulnerability
| Bugtraq ID: | 9017 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2003 12:00AM |
| Updated: | Nov 11 2003 12:00AM |
| Credit: | Discovery credited to Hisayuki Shinmachi. |
| Vulnerable: |
Fujitsu tsworks 3.0 |
| Not Vulnerable: |
Fujitsu tsworks 3.1 |
Discussion
Fujitsu tsworks Attachment Expansion Buffer Overflow Vulnerability
Fujitsu tsworks is vulnerable to a boundary condition error in the 'Expand the Attachment' feature. When an e-mail attachment containing an unusually long string of characters is expanded, an internal buffer can be overrun. Arbitrary code execution is possible.
Fujitsu tsworks is vulnerable to a boundary condition error in the 'Expand the Attachment' feature. When an e-mail attachment containing an unusually long string of characters is expanded, an internal buffer can be overrun. Arbitrary code execution is possible.
Exploit / POC
Fujitsu tsworks Attachment Expansion Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Fujitsu tsworks Attachment Expansion Buffer Overflow Vulnerability
Solution:
This issue has reportedly been fixed in tsworks 3.1, however, this has not been confirmed.
Fujitsu tsworks 3.0
Solution:
This issue has reportedly been fixed in tsworks 3.1, however, this has not been confirmed.
Fujitsu tsworks 3.0
-
Fujitsu tsworks 3.1
http://www.hnc.fujitsu.com/products/tsworks/update.html#ver3101
References
Fujitsu tsworks Attachment Expansion Buffer Overflow Vulnerability
References:
References:
- SNS Advisory No.70 (SNS)