PT-2006-4974 · Sap · Sap Internet Graphics Server
Mariano Nuñez Di Croce
·
Published
2006-08-14
·
Updated
2018-10-17
·
CVE-2006-4133
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP Internet Graphics Service (IGS) versions 6.40 and earlier
SAP Internet Graphics Service (IGS) versions 7.00 and earlier
Description
The issue allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request with an ADM:GETLOGFILE command and a long
portwatcher argument. This triggers the overflow during error message construction when the snprintf function returns a negative value that is used in a memcpy operation.Recommendations
For SAP Internet Graphics Service (IGS) versions 6.40 and earlier, update to a version later than 6.40 to resolve the issue.
For SAP Internet Graphics Service (IGS) versions 7.00 and earlier, update to a version later than 7.00 to resolve the issue.
As a temporary workaround, consider restricting access to the HTTP request with the ADM:GETLOGFILE command to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Internet Graphics Server