Email us! Subscribe to Liquidmatrix!

EMC NetWorker Remote Exec Buffer Overflow

This one leads to arbitrary code execution by a remote attacker.

From Secunia:

Description:
A vulnerability has been reported in EMC NetWorker, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error within the Networker Remote Exec Service (nsrexecd.exe). This can be exploited to cause a stack-based buffer overflow by sending a poll or kill request with an overly long, invalid subcmd to the service, which is available via a query to the portmapper on port 111/TCP for service #0×5f3e1, version 1.

Successful exploitation allows execution of arbitrary code.

The vulnerability is reported in version 7.x.x.

Solution:
The vendor has issued updates to correct this vulnerability. For more information see knowledge base article esg83899 (registration required) or contact the EMC Software Technical Support.

Article Link

Tags: , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • Trend Micro ServerProtect Buffer Overflow
  • Symantec NetBackup PureDisk PHP Buffer Overflow
  • QuickTime Multiple Vulnerabilities (Fire Bad)
  • WinDVD ActiveX Control Buffer Overflow
  • Snort Buffer Overflow
  • Leave a Comment