Search This Blog

Sunday, September 09, 2007

[NT] Trend Micro ServerProtect Stack Overflow Vulnerabilities

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Trend Micro ServerProtect Stack Overflow Vulnerabilities
------------------------------------------------------------------------


SUMMARY


<https://imperia.trendmicro-europe.com/us/products/enterprise/serverprotect-for-microsoft-windows/index.html> Trend Micro ServerProtect - "Prevent viruses from spreading through your network by blocking them before they reach the end user."

Two stack overflow vulnerabilities has been discovered in Trend Micro
ServerProtect software.

DETAILS

Vulnerable Systems:
* ServerProtect version 5.58

TMregChange() Stack Overflow Vulnerability:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Trend Micro Server Protect. Authentication is
not required to exploit this vulnerability.

The specific flaw exists within the routine TMregChange() exported by
TMReg.dll which is reachable through the custom protocol subcode
"\x15\x00\x00\x00". The TCP socket bound to port 5005 receives
user-supplied data which is copied without proper bounds checking to a
stack-based buffer. Thereby resulting in an exploitable condition.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4731>
CVE-2007-4731

RPCFN_SetComputerName() Stack Overflow Vulnerability:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Trend Micro ServerProtect. Authentication is
not required to exploit this vulnerability.

The specific flaw is exposed through the RPC interface bound on TCP port
5168 and defined in SpntSvc.exe with the following UUID:
25288888-bd5b-11d1-9d53-0080c83a5c2c

The vulnerable function, RPCFN_SetComputerName(), is reached when the
custom protocols "subcode" is set to "\x30\x00\x0a\x00". Improper use of
the MultiByteToWideChar() API results in an exploitable stack based buffer
overflow.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4218>
CVE-2007-4218

Vendor Response:
Trend Micro has issued an update to correct this vulnerability -
ServerProtect5.58 Security Patch 4 - Build 1185. More details can be found
at:

<http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch4_readme.txt> http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch4_readme.txt

Disclosure Timeline:
* 2007.07.17 - Vulnerability reported to vendor
* 2007.09.07 - Digital Vaccine released to TippingPoint customers
* 2007.09.07 - Coordinated public release of advisory


ADDITIONAL INFORMATION

The information has been provided by ZDI-07-051, ZDI-07-050.
The original article(s) can be found at:
<http://www.zerodayinitiative.com/advisories/ZDI-07-050.html>

http://www.zerodayinitiative.com/advisories/ZDI-07-050.html

<http://www.zerodayinitiative.com/advisories/ZDI-07-051.html>

http://www.zerodayinitiative.com/advisories/ZDI-07-051.html

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

31 comments:

Anonymous said...

valium generic trusted online pharmacy valium - valium medication pictures

Anonymous said...

buy xanax online forum false negative drug test xanax - generic xanax orange round

Anonymous said...

discount xanax xanax side effects uti - prozac xanax and alcohol

Anonymous said...

buy ambien generic ambien 54 553 - ambien side effects with alcohol

Anonymous said...

diazepam drug que es mejor diazepam o tranxilium - diazepam dosage range

Anonymous said...

buy xanax online xanax dosage wiki - generic xanax xr 1mg

Anonymous said...

buy ativan ativan 0.5 mg tablet - order ativan online in canada

Anonymous said...

buy valium overnight delivery valium narcotic drug - 10mg valium price

Anonymous said...

buy diazepam diazepam side effects dry mouth - diazepam dosage pictures

Anonymous said...

cheap diazepam online diazepam dosage dogs - diazepam urine test

Anonymous said...

discount xanax xanax bars youtube - xanax drug mechanism

Anonymous said...

zolpidem high zolpidem side effects pregnancy - zolpidem generic

Anonymous said...

cheap ativan online overdose ativan klonopin - ativan xanax conversion

Anonymous said...

ativan pharmacy buy ativan in canada - ativan side effects psychosis

Anonymous said...

buy ativan lorazepam 1mg 50 comprimidos - combining ativan and alcohol

Anonymous said...

buy xanax online forum xanax normal dose - xanax no prescription review

Anonymous said...

buy valium india valium rx 7 - valium side effects mayo

Anonymous said...

buy diazepam online retail price valium - valium makes depression worse

Anonymous said...

soma cheap carisoprodol side effects abuse - carisoprodol image

Anonymous said...

buy valium online without prescription do they drug test valium - valium dosage claustrophobia

Anonymous said...

buy soma carisoprodol high feeling - soma drug back pain

Anonymous said...

buy soma online drug enforcement agency soma - soma drug dosage

Anonymous said...

buy valium online valium high bp - buy valium in australia

Anonymous said...

buy ambien online ambien use get high - online drugstore 24 ambien

Anonymous said...

buy valium online buy valium online no prescription uk - what does a valium pill do

Anonymous said...

Hi, MoxoredapeTox cheap propecia online - propecia online no prescription http://www.bigdocpoker.com/#buy-cheap-propecia

Anonymous said...

Online Drug Venders sibutramine for sale - buy meridia http://www.meridiaonlineorder.net/#buy-meridia , [url=http://www.meridiaonlineorder.net/#meridia-online ]meridia online [/url]

Anonymous said...

2, order finasteride online - cheap finasteride 5mg http://www.wheretobuymedsonline.com/propecia/], [url=http://www.wheretobuymedsonline.com/propecia/]cheap generic propecia [/url]

Anonymous said...

4, provigil for sale - modafinil price http://www.provigilonlineoffer.net/, [url=http://www.provigilonlineoffer.net/]buy modafinil without prescription [/url]

Anonymous said...

6, nexium without rx - esomeprazole online - nexium cost http://www.nexiumpricewatch.net/.

Anonymous said...

5, Nexium No Prescription - Cheap Nexium - generic nexium no prescription http://www.nexiumpricewatch.net/ .