SARA Server远程缓冲区溢出漏洞

SARA Server远程缓冲区溢出漏洞

漏洞ID 1108063 漏洞类型 边界条件错误
发布时间 2004-07-20 更新时间 2005-10-20
图片[1]-SARA Server远程缓冲区溢出漏洞-安全小百科CVE编号 CVE-2004-1728
图片[2]-SARA Server远程缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200408-203
漏洞平台 Multiple CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/24386
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200408-203
|漏洞详情
SARAServer是BritishNational校园网的服务程序。SARAServer存在多个缓冲区溢出,远程攻击者可以利用这个漏洞可能以进程权限在系统上执行任意指令。提交类似如下的畸形请求,可导致程序发生缓冲区溢出:perl-e’print”SUCK”x11;printchrforeach(0x90,0xdb,0x14,0x40,0);’|netcatvictim7000精心构建提交数据可能以进程权限在系统上执行任意指令。
|漏洞EXP
source: http://www.securityfocus.com/bid/10984/info

sarad is reported prone to a buffer overflow vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data.

A remote attacker can trigger the overflow condition by supplying a large string value to the application. Arbitrary code execution is possible in the context of the server.

In addition to this issue, it is reported that various other instances of potential buffer overflow and format string vulnerabilities exist throughout the application. These issues exist due to the use of strcpy() and sprintf functions. This BID will be updated upon further analysis.

perl -e 'print "SUCK" x 11; print chr foreach(0x90,0xdb,0x14,0x40,0);' | netcat victim 7000
|参考资料

来源:XF
名称:sara-server-bo(17060)
链接:http://xforce.iss.net/xforce/xfdb/17060
来源:BID
名称:10984
链接:http://www.securityfocus.com/bid/10984
来源:SECUNIA
名称:12348
链接:http://secunia.com/advisories/12348
来源:BUGTRAQ
名称:20040820Bufferoverflowinsarad
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109308454122827&w;=2

相关推荐: ChiTeX Local Privilege Escalation Vulnerability

ChiTeX Local Privilege Escalation Vulnerability 漏洞ID 1100528 漏洞类型 Design Error 发布时间 2003-04-03 更新时间 2003-04-03 CVE编号 N/A CNNVD-ID …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享