PT-2008-5204 · Trend Micro · Trend Micro Officescan

Publicado

2008-10-23

·

Atualizado

2018-10-11

·

CVE-2008-3862

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro OfficeScan versions 7.3 Patch 4 build 1367 through 7.3 Patch 4 build 1373 Trend Micro OfficeScan version 8.0 SP1 Patch 1 before build 3110
Description The issue is related to a stack-based buffer overflow in CGI programs within the server, allowing remote attackers to execute arbitrary code via an HTTP POST request containing crafted form data. This is related to the parsing of CGI requests.
Recommendations For Trend Micro OfficeScan versions 7.3 Patch 4 build 1367 through 7.3 Patch 4 build 1373, update to build 1374 or later. For Trend Micro OfficeScan version 8.0 SP1 Patch 1 before build 3110, update to build 3110 or later. As a temporary workaround, consider restricting access to CGI programs within the server to minimize the risk of exploitation.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3862

Produtos afetados

Trend Micro Officescan