PT-2015-7420 · Borland+1 · Borland Accurev+1

Rgod

·

Publicado

2015-09-02

·

Atualizado

2019-06-26

·

CVE-2015-6946

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Borland AccuRev (affected versions not specified)
Description The issue concerns multiple stack-based buffer overflows in the Reprise License Manager service. These overflows can be triggered by remote attackers through specific parameters, including the actserver and akey parameters to the activate doit function, as well as the licfile parameter to the service startup doit functionality. This allows attackers to execute arbitrary code.
Recommendations For the activate doit function, consider disabling the use of the actserver and akey parameters until a patch is available. Restrict access to the service startup doit functionality to minimize the risk of exploitation through the licfile parameter. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6946
ZDI-15-412
ZDI-15-414
ZDI-15-416

Produtos afetados

Borland Accurev
Reprise License Manager