Описание
Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2) cause a denial of service (daemon crash) on Windows platforms via a long username field during backup domain authentication, related to nnwindtb.dll. NOTE: some of these details are obtained from third party information.
Комментарий
Per: http://secunia.com/advisories/34024
Successful exploitation allows to crash the application on a Windows system and reportedly allows to execute arbitrary code on a Linux system.
Ссылки
- Broken Link
- Broken Link
- Vendor Advisory
- URL Repurposed
- ExploitThird Party AdvisoryVDB Entry
- VDB Entry
- Broken Link
- Broken Link
- Vendor Advisory
- URL Repurposed
- ExploitThird Party AdvisoryVDB Entry
- VDB Entry
Уязвимые конфигурации
Одновременно
EPSS
7.5 High
CVSS2
Дефекты
Связанные уязвимости
Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2) cause a denial of service (daemon crash) on Windows platforms via a long username field during backup domain authentication, related to nnwindtb.dll. NOTE: some of these details are obtained from third party information.
EPSS
7.5 High
CVSS2