LANDesk Software LANDesk Management Suite IRCBoot.DLL ActiveX Control Buffer Overrun Vulnerability
BID:9304
Info
LANDesk Software LANDesk Management Suite IRCBoot.DLL ActiveX Control Buffer Overrun Vulnerability
| Bugtraq ID: | 9304 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 27 2003 12:00AM |
| Updated: | Dec 27 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Tri Huynh" <[email protected]>. |
| Vulnerable: |
LANDesk Software LANDesk Management Suite 8.0 LANDesk Software LANDesk Management Suite 7.0 LANDesk Software LANDesk Management Suite 6.63 LANDesk Software LANDesk Management Suite 6.62 LANDesk Software LANDesk Management Suite 6.4 LANDesk Software LANDesk Management Suite 6.0 |
| Not Vulnerable: | |
Discussion
LANDesk Software LANDesk Management Suite IRCBoot.DLL ActiveX Control Buffer Overrun Vulnerability
A problem has been identified in the handling of some types of requests by ActiveX controls installed with LANDesk Management Suite. Because of this, it may be possible for an attacker to execute arbitrary code on a vulnerable host.
A web page containing a malicious call to the vulnerable ActiveX control and a malicious string passed as an argument to the affected function, could potentially exploit this issue to execute code with the privileges of the browser user.
A problem has been identified in the handling of some types of requests by ActiveX controls installed with LANDesk Management Suite. Because of this, it may be possible for an attacker to execute arbitrary code on a vulnerable host.
A web page containing a malicious call to the vulnerable ActiveX control and a malicious string passed as an argument to the affected function, could potentially exploit this issue to execute code with the privileges of the browser user.
Exploit / POC
LANDesk Software LANDesk Management Suite IRCBoot.DLL ActiveX Control Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
LANDesk Software LANDesk Management Suite IRCBoot.DLL ActiveX Control Buffer Overrun Vulnerability
Solution:
The vendor has released fixes to address this issue for LANDesk Management Suite versions 8, 7, and 6.62.
LANDesk Software LANDesk Management Suite 6.62
LANDesk Software LANDesk Management Suite 7.0
LANDesk Software LANDesk Management Suite 8.0
Solution:
The vendor has released fixes to address this issue for LANDesk Management Suite versions 8, 7, and 6.62.
LANDesk Software LANDesk Management Suite 6.62
-
LANDesk Software ot Fix 335708 for LANDesk® Management Suite 6.62
http://support.landesk.com/support/downloads.php?id=168&&name=33570662 .zip&&prod=662&&type=hot%20fix
LANDesk Software LANDesk Management Suite 7.0
-
LANDesk Software Hot Fix 335708 for LANDesk® Management Suite 7
http://support.landesk.com/support/downloads.php?id=167&&name=3357070. zip&&prod=70&&type=hot%20fix
LANDesk Software LANDesk Management Suite 8.0
-
LANDesk Software Hot Fix 335708 for LANDesk® Management Suite 8
http://support.landesk.com/support/downloads.php?id=166&&name=335708.z ip&&prod=8&&type=hot%20fix
References
LANDesk Software LANDesk Management Suite IRCBoot.DLL ActiveX Control Buffer Overrun Vulnerability
References:
References:
- Updated: 05/01/2004 (LANDesk Software)
- Vendor Homepage (LANDesk Software)
- Landesk Management Suite IRCRBOOT.DLL buffer overflow ("Tri Huynh"
)