PT-2009-6084 · Eeye · Eeye Retina Network Security Scanner+1
Gjoko Krstic
+1
·
Publicado
2009-11-04
·
Atualizado
2017-09-19
·
CVE-2009-3859
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
eEye Retina WiFi Scanner version 1.0.8.68
Retina Network Security Scanner version 5.10.14
Description
The issue allows user-assisted remote attackers to cause a denial of service or execute arbitrary code via a .rws file with a long RWS010 entry. This can lead to an application crash or potentially more severe consequences.
Recommendations
For eEye Retina WiFi Scanner version 1.0.8.68, avoid using .rws files with long RWS010 entries until a fix is available.
For Retina Network Security Scanner version 5.10.14, restrict the use of the WiFi Scanner component to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eeye Retina Network Security Scanner
Eeye Retina Wifi Scanner