|
 |
|
H-Sphere buffer overflow
|
|
|
|
|
Secunia Advisory:
|
SA7832
|
|
|
Release Date:
|
2003-01-08
|
|
|
Critical:
|

Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | H-Sphere 2.x
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: H-Sphere has been found vulnerable to a remotely exploitable buffer overflow.
The problem exists in the webshell binary, which is installed suid root. The problem is that the boundary tags aren't verified, by supplying boundary tags of more than 300 characters EIP is over written, this allows arbitrary code to be executed as root.
Solution: Install this patch:
http://www.psoft.net/misc/webshell_patch.html
http://psoft.net/shiv/U23/u-webshell.tgz
Provided and/or discovered by: Carl Livitt
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
8 Related Secunia Security Advisories
|
|
|
1. H-Sphere SiteStudio Unspecified Vulnerability
|
|
2. H-Sphere SiteStudio "template" Information Disclosure
|
|
3. H-Sphere Control Panel Insecure Permissions of Logfiles
|
|
4. H-Sphere Multiple Cross-Site Scripting Vulnerabilities
|
|
5. H-Sphere "login" Cross-Site Scripting Vulnerability
|
|
6. H-Sphere Exposure of User Credentials
|
|
7. SiteStudio and H-Sphere "name" Script Insertion Vulnerability
|
|
8. H-Sphere Cross Site Scripting
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|