PT-2010-1453 · Juniper Networks · Juniper Odyssey Access Client

Publicado

2010-02-15

·

Atualizado

2010-02-16

·

CVE-2009-4643

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Juniper Odyssey Access Client version 4.72.11421.0
Description The issue is related to a stack-based buffer overflow in the dsInstallerService.dll component of the Juniper Installer Service. This can be exploited by remote attackers who send a long string in a malformed DSSETUPSERVICE CMD UNINSTALL command to the NeoterisSetupService named pipe, allowing them to execute arbitrary code.
Recommendations For Juniper Odyssey Access Client version 4.72.11421.0, consider restricting access to the NeoterisSetupService named pipe until a patch is available. As a temporary workaround, avoid using the DSSETUPSERVICE CMD UNINSTALL command with long strings. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4643

Produtos afetados

Juniper Odyssey Access Client