Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800392
Kategorie:Buffer overflow
Titel:SlySoft Products Code Execution Vulnerability (CVE-2009-0824)
Zusammenfassung:SlySoft Products is prone to a Code Execution Vulnerability.
Beschreibung:Summary:
SlySoft Products is prone to a Code Execution Vulnerability.

Vulnerability Insight:
METHOD_NEITHER communication method for IOCTLs does not properly validate
a buffer associated with the Irp object of user space data provided to
the ElbyCDIO.sys kernel driver.

Vulnerability Impact:
Successful exploitation will let the attacker cause memory corruption and
can allow remote code execution in the context of the affected system,
which result in service crash.

Affected Software/OS:
SlySoft AnyDVD version prior to 6.5.2.6.

SlySoft CloneCD version 5.3.1.3 and prior.

SlySoft CloneDVD version 2.9.2.0 and prior.

SlySoft Virtual CloneDrive version 5.4.2.3 and prior.

Solution:
Upgrade to higher versions accordingly.

CVSS Score:
4.9

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-0824
BugTraq ID: 34103
http://www.securityfocus.com/bid/34103
Bugtraq: 20090312 [Suspected Spam][PT-2009-11] SlySoft Multiple Products ElbyCDIO.sys Denial of Service (Google Search)
http://www.securityfocus.com/archive/1/501713/100/0/threaded
http://en.securitylab.ru/lab/PT-2009-11
http://osvdb.org/52679
http://secunia.com/advisories/34269
http://secunia.com/advisories/34287
http://secunia.com/advisories/34288
http://secunia.com/advisories/34289
XForce ISS Database: slysoft-elbycdio-dos(49232)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49232
CopyrightCopyright (C) 2009 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.