首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
IBM solidDB <= 6.5.0.3 Denial of Service Vulnerability
来源:aluigi.org 作者:Auriemma 发布时间:2010-10-18  

Source: http://aluigi.org/adv/soliddb_1-adv.txt
#######################################################################

                             Luigi Auriemma

Application:  IBM solidDB
              http://www-01.ibm.com/software/data/soliddb/
Versions:     <= 6.5.0.3
Platforms:    AIX, Linux, Solaris, Windows
Bug:          Denial of Service
Exploitation: remote, versus server
Date:         15 Oct 2010
Author:       Luigi Auriemma
              e-mail: aluigi@autistici.org
              web:    aluigi.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


"IBM solidDB product family features relational, in-memory database
technology that delivers extreme speed, performing up to ten times
faster than conventional, disk-based databases."


#######################################################################

======
2) Bug
======


The solid.exe service listening on port 1315 can be crashed by an
external attacker through a malformed type of packet.
The bugged function is located at address 0063dc60 which is called
recursively if the packet contains a particular value between the range
of values 15001 and 15100 (switch 9).
The effects of the problem can be:
- stack exaustion by using over 14000 of these values so that all the
  memory of the stack gets consumed by these recursive callings
- NULL pointer due to the usage of only one of these values where an
  unused pointer (set to zero) is used in a comparison operation
- invalid memory access by using also another type of value after those


#######################################################################

===========
3) The Code
===========


http://aluigi.org/poc/soliddb_1.zip
http://www.exploit-db.com/sploits/soliddb_1.zip

#######################################################################

======
4) Fix
======


No fix.


#######################################################################


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Rocket Software UniData <= 7.2
·Microsoft Office HtmlDlgHelper
·PCDJ Karaoki 0.6.3819 Denial o
·ConvexSoft DJ Audio Mixer Deni
·Ease Jukebox v1.30 Denial of S
·PHP Hosting Directory 2.0 Data
·postcard mentor (ing) (guncell
·MS10-070 ASP.NET Padding Oracl
·e-kart (tr) Database Disclosur
·Windows NTLM Weak Nonce Vulner
·Multiple Buffer Overflows in W
·Novel eDirectory DHost Console
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved