Multiple Vendor XFERWAN.EXE Filename Remote Buffer Overflow Vulnerability

TITLE: Multiple Vendor XFERWAN.EXE Filename Remote Buffer Overflow Vulnerability
CLASS: Boundary Condition Error
CVE: CVE-2007-2514

REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 04 2007 12:00AM
UPDATE: Jun 04 2007 12:00AM
CREDIT: Discovered by Cody Pierce, TippingPoint DVLabs.
VULNERABLE:

Symantec Discovery 6.5
Numara Numara Asset Manager 8.0
Centennial UK Ltd Discovery 2006 Feature Pack 1
NOT VULNERABLE:

Vai alla pagina originale su Security Focus

Discussion

Multiple Vendor products are prone to a remote buffer-overflow vulnerability in 'XFERWAN.EXE'.

The vulnerability arises in the service when handling logging requests. Specifically, a long filename can trigger an overflow condition leading to memory corruption.

A remote attacker may trigger a denial-of-service condition or may execute arbitrary code with SYSTEM privileges. This may facilitate a complete compromise of affected systems.

The following versions are considered to be vulnerable as they contain the affected executable:

Centennial Discovery 2006 Feature Pack 1
Symantec Discovery 6.5
Numara Asset Manager 8.0

Earlier versions of each application may be affected as well.

Exploit

It is possible that an exploit for this issue has been developed by the researcher responsible for discovering this issue however, Symantec is not aware of any reports that the exploit is publicly available. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.

Solution

Solution:
Reports indicate that Centennial has released a patch that addresses this issue. The fix may be available in the Centennial Customer Zone support site. Please contact the vendor references for more information. It should be noted that Symantec has not verified this information.

References

References:

PhpLog

BNLug Benevento Linux Users Group