Computer Security
[EN] securityvulns.ru no-pyccku


SBLIM SFCB multiple security vulnerabilities
Published:03.06.2010
Source:
SecurityVulns ID:10900
Type:remote
Threat Level:
7/10
Description:Buffer overflow and integer overflow in TCP/5988, TCP/5989 interfaces.
Affected:SBLIM : Small Footprint CIM Broker 1.3
CVE:CVE-2010-2054 (Integer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB 1.3.4 through 1.3.7, when the configuration sets httpMaxContentLength to a zero value, allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a large integer in the Content-Length HTTP header, aka bug #3001915. NOTE: some of these details are obtained from third party information.)
 CVE-2010-1937 (Heap-based buffer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB before 1.3.8 might allow remote attackers to execute arbitrary code via a Content-Length HTTP header that specifies a value too small for the amount of POST data, aka bug #3001896.)
Original documentdocumentNicolas Grégoire, SFCB vulnerabilities (03.06.2010)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod