PT-2001-2110 · Trend Micro · Femanager+7
Publicado
2001-09-12
·
Atualizado
2017-12-19
·
CVE-2001-0958
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Trend Micro InterScan VirusWall for NT versions 3.51 and 3.51J
Description
The issue allows remote attackers to execute arbitrary code due to buffer overflows in the eManager plugin. This is achieved by providing long arguments to various CGI programs, including "register.dll", "ContentFilter.dll", "SFNofitication.dll", "TOP10.dll", "SpamExcp.dll", and "spamrule.dll".
Recommendations
For Trend Micro InterScan VirusWall for NT versions 3.51 and 3.51J, consider disabling the eManager plugin until a patch is available to prevent exploitation of the buffer overflows in the CGI programs. Restrict access to the affected CGI programs to minimize the risk of arbitrary code execution.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Contentfilter.Dll
Sfnofitication.Dll
Spamexcp.Dll
Top10.Dll
Trend Micro Interscan Viruswall
Femanager
Register.Dll
Spamrule.Dll