首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Rocket Software UniData <= 7.2.7.3806 Denial of Service Vulnerabilities
来源:aluigi.org 作者:Auriemma 发布时间:2010-10-18  

Source: http://aluigi.org/adv/unirpcd_1-adv.txt
#######################################################################

                             Luigi Auriemma

Application:  Rocket Software UniData
              http://www.rocketsoftware.com/u2/products/unidata/
Versions:     <= 7.2.7.3806
Platforms:    Windows
Bugs:         various Denial of Service vulnerabilities in unirpcd.exe
Exploitation: remote, versus server
Date:         15 Oct 2010
Author:       Luigi Auriemma
              e-mail: aluigi@autistici.org
              web:    aluigi.org


#######################################################################


1) Introduction
2) Bugs
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


"UniData® is an extended relational data server ideal for embedding in
a variety of industry-focused solutions."


#######################################################################

=======
2) Bugs
=======


The unirpc service listening on port 31438 is affected by various
Denial of Service vulnerabilities regarding the access of invalid zones
of memory.

Although the first vulnerability is a memory corruption problem where
the program calls recv() using a heap buffer and a huge amount of data
to copy (like 0x7fffffe8, decided by the attacker) in my tests it
didn't result exploitable.


#######################################################################

===========
3) The Code
===========


http://aluigi.org/poc/unirpcd_1.zip
http://www.exploit-db.com/sploits/unirpcd_1.zip

#######################################################################

======
4) Fix
======


No fix.


#######################################################################


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·PCDJ Karaoki 0.6.3819 Denial o
·IBM solidDB <= 6.5.0.3 Denial
·Ease Jukebox v1.30 Denial of S
·Microsoft Office HtmlDlgHelper
·postcard mentor (ing) (guncell
·ConvexSoft DJ Audio Mixer Deni
·e-kart (tr) Database Disclosur
·PHP Hosting Directory 2.0 Data
·Multiple Buffer Overflows in W
·MS10-070 ASP.NET Padding Oracl
·Oracle Solaris CVE-2010-3503 '
·Windows NTLM Weak Nonce Vulner
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved