DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability
BID:9213
Info
DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability
| Bugtraq ID: | 9213 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-1030 CVE-2003-1030 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2003 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | Vulnerability discovery credited to wirepair. |
| Vulnerable: |
DameWare Development Mini Remote Control Server 3.72 .0.0 DameWare Development Mini Remote Control Server 3.71 .0.0 DameWare Development Mini Remote Control Server 3.70 .0.0 |
| Not Vulnerable: |
DameWare Development Mini Remote Control Server 4.0 DameWare Development Mini Remote Control Server 3.73 .0.0 |
Discussion
DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability
A problem has been identified in the handling of pre-authentication packets by DameWare Mini Remote Control Server. Because of this, it may be possible for a remote attacker to gain unauthorized access to hosts using the vulnerable software.
A problem has been identified in the handling of pre-authentication packets by DameWare Mini Remote Control Server. Because of this, it may be possible for a remote attacker to gain unauthorized access to hosts using the vulnerable software.
Exploit / POC
DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability
Exploit contributed by Adik, additional exploit contributed by kralor.
Exploit contributed by Adik, additional exploit contributed by kralor.
Solution / Fix
DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability
Solution:
This issue has been resolved in version 3.73 and later (including version 4.0). Users should contact the vendor to obtain upgrades.
Solution:
This issue has been resolved in version 3.73 and later (including version 4.0). Users should contact the vendor to obtain upgrades.
References
DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow Vulnerability
References:
References:
- DameWare Mini Remote Control Server Product Page (DameWare Development)
- DameWare Mini Remote Control < v3.73 remote exploit by kralor] ( =?iso-8859-1?Q?Iv=E1n_Rodriguez_Almui=F1a?=
) - DameWare Mini Remote Control Server <= 3.72 Buffer Overflow ("wirepair"
)