PT-2001-2110 · Trend Micro · Femanager+7

Publicado

2001-09-12

·

Atualizado

2017-12-19

·

CVE-2001-0958

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan VirusWall for NT versions 3.51 and 3.51J
Description The issue allows remote attackers to execute arbitrary code due to buffer overflows in the eManager plugin. This is achieved by providing long arguments to various CGI programs, including "register.dll", "ContentFilter.dll", "SFNofitication.dll", "TOP10.dll", "SpamExcp.dll", and "spamrule.dll".
Recommendations For Trend Micro InterScan VirusWall for NT versions 3.51 and 3.51J, consider disabling the eManager plugin until a patch is available to prevent exploitation of the buffer overflows in the CGI programs. Restrict access to the affected CGI programs to minimize the risk of arbitrary code execution.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0958

Produtos afetados

Contentfilter.Dll
Sfnofitication.Dll
Spamexcp.Dll
Top10.Dll
Trend Micro Interscan Viruswall
Femanager
Register.Dll
Spamrule.Dll