Section: .. / 0801-advisories /
| /// File Name: |
yasslick.txt |
Description:
|
yaSSL versions 1.75 and below suffer from invalid memory access and buffer overflow vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | yasslick.zip | | File Size: | 4738 | | Last Modified: | Jan 4 20:22:28 2008 |
| MD5 Checksum: | ca567cce4d6d28609d58393922207d08 |
|
| /// File Name: |
ZDI-08-001.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Storage Manager Express. Authentication is not required to exploit this vulnerability. The specific flaw resides in the TSM Express Backup Server service, dsmsvc.exe, which listens by default on TCP port 1500. The process trusts a user-supplied length value. By supplying a large number, an attacker can overflow a static heap buffer leading to arbitrary code execution in the context of the SYSTEM user. Tivoli Storage Manager Express version 5.3 is affected.
| | Author: | Tenable Network Security,Sebastian Apelt | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3054 | | Related CVE(s): | CVE-2008-0247 | | Last Modified: | Jan 14 17:38:21 2008 |
| MD5 Checksum: | 7a0c52554fa38a18476a3e556c03e3d5 |
|
| /// File Name: |
ZDI-08-002.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Citrix Presentation Server. Authentication is not required to exploit this vulnerability. The specific flaw resides in the Independent Management Architecture service, ImaSrv.exe, which listens by default on TCP port 2512 or 2513. The process trusts a user-suppled value as a parameter to a memory allocation. By supplying a specific value, an undersized heap buffer may be allocated. Subsequently, an attacker can then overflow that heap buffer by sending an overly large packet leading to arbitrary code execution in the context of the SYSTEM user.
| | Author: | Eric DETOISIEN | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3437 | | Last Modified: | Jan 18 05:38:14 2008 |
| MD5 Checksum: | b633e3e2771697f71e17271da86d5369 |
|
|
|
|
|