Trend Micro OfficeScan CGI Modules Buffer Overflow and Authentication Bypass
Secunia Advisory: SA25778
Release Date: 2007-06-26
Critical: Moderately critical
Impact: Security Bypass System access
Where: From local network
Solution Status: Vendor Patch
Software: Trend Micro OfficeScan Corporate Edition 8.x
Description:
Two vulnerabilities have been reported in Trend Micro OfficeScan, which can be exploited by malicious people to bypass certain security restrictions or compromise a vulnerable system.
1) A boundary error within a CGI module can be exploited to cause a buffer overflow and execute arbitrary code.
2) An unspecified error within a CGI module can be exploited to bypass the authentication mechanism of the OfficeScan Management Console via a specially crafted HTTP header.
The vulnerabilities affect OfficeScan Corporate Edition version 8.0.
Solution:
Apply Security Patch - Build 1042:
http://www.trendmicro.com/ftp/product...sce_80_win_en_securitypatch_b1042.exe
Provided and/or discovered by:
Reported by the vendor.