PT-2010-1453 · Juniper Networks · Juniper Odyssey Access Client
Publicado
2010-02-15
·
Atualizado
2010-02-16
·
CVE-2009-4643
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Odyssey Access Client version 4.72.11421.0
Description
The issue is related to a stack-based buffer overflow in the dsInstallerService.dll component of the Juniper Installer Service. This can be exploited by remote attackers who send a long string in a malformed
DSSETUPSERVICE CMD UNINSTALL command to the NeoterisSetupService named pipe, allowing them to execute arbitrary code.Recommendations
For Juniper Odyssey Access Client version 4.72.11421.0, consider restricting access to the
NeoterisSetupService named pipe until a patch is available. As a temporary workaround, avoid using the DSSETUPSERVICE CMD UNINSTALL command with long strings. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Juniper Odyssey Access Client