Computer Security
[EN] securityvulns.ru
no-pyccku





CommuniGatePro 3.1 for NT DoS




CommuniGatePro 3.1 for NT DoS





=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

   Date: Пт, 03 дек 1999  20:26:07
  От: Nobuo Miwa <n-miwa@LAC.CO.JP>
Кому: BUGTRAQ@SECURITYFOCUS.COM
Тема: CommuniGatePro 3.1 for NT DoS
--------------------------------------------------------------------------------


Hi,

I reported a buffer overflow vulnerability on CommuniGatePro 3.1 for NT
to support@stalker.com. And they fixed immediately.

It's simple buffer overflow, actually.

 1. connect to port 8010 (http configuration from remote browser)
 2. send 70000 of 'a' + "\r\n"
 3. connect to any port(25,8010,..) just like "telnet server 25"
 4. Access violation

Their reply is following..
 Fixed in the current 3.2 betas. Please install either the 3.2b5 or the
 3.2b7 that should be out by Monday - 3.2b6 had many internal changes
 and a couple of bugs have been found there.


<Nobuo Miwa> n-miwa@lac.co.jp  ( @ @ ) http://www.lac.co.jp/security/
--------------------------o00o--(. .)--o00o--------------------------


About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru