Luigi Auriemma has discovered two vulnerabilities in RealWin, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
1) A boundary error when processing "SCPC_INITIALIZE" and "SCPC_INITIALIZE_RF" packets can be exploited to cause a stack-based buffer overflow by e.g. sending specially crafted packets to port 912/TCP.
2) A boundary error when processing the "SCPC_TXTEVENT" packets can be exploited to cause a stack-based buffer overflow by e.g. sending a specially crafted packet to port 912/TCP.
The vulnerabilities are confirmed in RealWin 2.1 Build 18.104.22.168. Other versions may also be affected.
Solution: Reportedly fixed in version 2.1.10 (2.1 Build 22.214.171.124).
Provided and/or discovered by: Luigi Auriemma
Original Advisory: http://aluigi.altervista.org/adv/realwin_1-adv.txt
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to email@example.com