PT-2001-2110 · Trend Micro · Femanager+7

Published

2001-09-12

·

Updated

2017-12-19

·

CVE-2001-0958

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan VirusWall for NT versions 3.51 and 3.51J
Description The issue allows remote attackers to execute arbitrary code due to buffer overflows in the eManager plugin. This is achieved by providing long arguments to various CGI programs, including "register.dll", "ContentFilter.dll", "SFNofitication.dll", "TOP10.dll", "SpamExcp.dll", and "spamrule.dll".
Recommendations For Trend Micro InterScan VirusWall for NT versions 3.51 and 3.51J, consider disabling the eManager plugin until a patch is available to prevent exploitation of the buffer overflows in the CGI programs. Restrict access to the affected CGI programs to minimize the risk of arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0958

Affected Products

Contentfilter.Dll
Sfnofitication.Dll
Spamexcp.Dll
Top10.Dll
Trend Micro Interscan Viruswall
Femanager
Register.Dll
Spamrule.Dll