PT-2009-6084 · Eeye · Eeye Retina Network Security Scanner+1
Gjoko Krstic
+1
·
Published
2009-11-04
·
Updated
2017-09-19
·
CVE-2009-3859
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
eEye Retina WiFi Scanner version 1.0.8.68
Retina Network Security Scanner version 5.10.14
Description
The issue allows user-assisted remote attackers to cause a denial of service or execute arbitrary code via a .rws file with a long RWS010 entry. This can lead to an application crash or potentially more severe consequences.
Recommendations
For eEye Retina WiFi Scanner version 1.0.8.68, avoid using .rws files with long RWS010 entries until a fix is available.
For Retina Network Security Scanner version 5.10.14, restrict the use of the WiFi Scanner component to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eeye Retina Network Security Scanner
Eeye Retina Wifi Scanner