Trend Micro OfficeScan CGI Modules Buffer Overflow and Authentication Bypass      

Secunia Advisory:  SA25778    


Release Date:  2007-06-26 


Critical:  Moderately critical 

Impact:  Security Bypass   System access


Where:  From local network

Solution Status:  Vendor Patch


Software: Trend Micro OfficeScan Corporate Edition 8.x

Description:


Two vulnerabilities have been reported in Trend Micro OfficeScan, which can be exploited by malicious people to bypass certain security restrictions or compromise a vulnerable system.

1) A boundary error within a CGI module can be exploited to cause a buffer overflow and execute arbitrary code.

2) An unspecified error within a CGI module can be exploited to bypass the authentication mechanism of the OfficeScan Management Console via a specially crafted HTTP header.

The vulnerabilities affect OfficeScan Corporate Edition version 8.0.

Solution:


Apply Security Patch - Build 1042:


http://www.trendmicro.com/ftp/product...sce_80_win_en_securitypatch_b1042.exe

Provided and/or discovered by:


Reported by the vendor.


arrow
arrow
    全站熱搜
    創作者介紹
    創作者 jason0936 的頭像
    jason0936

    J漾諸事會社

    jason0936 發表在 痞客邦 留言(0) 人氣()