Secunia
|
|

|
|
|
|
|
|
|
Release Date: 2007-02-21 Last Update: 2007-05-11 Views: 15,340
Where:
From local network
Impact:
System access,
Solution Status:
Vendor Patch
Software:
CVE Reference(s):
TippingPoint Security Research Team has reported some vulnerabilities in Trend Micro ServerProtect, which can be exploited by malicious people to compromise a vulnerable system.
1) A boundary error within the "CMON_NetTestConnection()" function in StCommon.dll can be exploited to cause a stack-based buffer overflow via a specially crafted RPC request to the SpntSvc.exe service (default port 5168/TCP).
2) A boundary error within the "ENG_SendEMail()" function in eng50.dll can be exploited to cause a stack-based buffer overflow via a specially crafted RPC request to the SpntSvc.exe service.
Successful exploitation of the vulnerabilities allows execution of arbitrary code with SYSTEM privileges.
The vulnerabilities are reported in the following versions:
* ServerProtect for Windows 5.58
* ServerProtect for EMC 5.58
* ServerProtect for Network Appliance Filer 5.61
* ServerProtect for Network Appliance Filer 5.62
Solution:
Apply patches.
Further details available to Secunia VIM customers
Provided and/or discovered by:
Pedram Amini, TippingPoint Security Research Team.
Original Advisory:
Trend Micro:
http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290
TippingPoint:
http://www.tippingpoint.com/security/advisories/TSRT-07-01.html
http://www.tippingpoint.com/security/advisories/TSRT-07-02.html
Deep Links:
Links available to Secunia VIM customers
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
Subject: Trend Micro ServerProtect Buffer Overflow Vulnerabilities
|
No posts yet |
|
You must be logged in to post a comment. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |