![]() |
Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | ||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.800063 |
Kategorie: | Denial of Service |
Titel: | WinComLPD Total Multiple Vulnerabilities |
Zusammenfassung: | WinComLPD Total is prone to buffer overflow and authentication bypass vulnerabilities. |
Beschreibung: | Summary: WinComLPD Total is prone to buffer overflow and authentication bypass vulnerabilities. Vulnerability Insight: The issues are due to: - an error in Line Printer Daemon Service (LPDService.exe), when processing print jobs with an overly long control file on default TCP port 515/13500. - an error in authentication checks in the Line Printer Daemon (LPD). Vulnerability Impact: Successful exploitation could allow execution of arbitrary code or crashing the remote wincomlpd service by simply using negative values like 0x80/0xff for the 8 bit numbers and 0x8000/0xffff for the data blocks. Affected Software/OS: WinCom LPD Total 3.0.2.623 and prior on Windows. Solution: No known solution was made available for at least one year since the disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-5158 BugTraq ID: 27614 http://www.securityfocus.com/bid/27614 Bugtraq: 20080204 Multiple vulnerabilities in WinCom LPD Total 3.0.2.623 (Google Search) http://www.securityfocus.com/archive/1/487507/100/200/threaded http://aluigi.org/adv/wincomalpd-adv.txt http://aluigi.org/poc/wincomalpd.zip http://secunia.com/advisories/28763 http://securityreason.com/securityalert/4610 http://www.vupen.com/english/advisories/2008/0410 Common Vulnerability Exposure (CVE) ID: CVE-2008-5159 Common Vulnerability Exposure (CVE) ID: CVE-2008-5176 |
Copyright | Copyright (C) 2008 Greenbone AG |
Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |