[NEWS] CiscoWorks Internetwork Performance Monitor Command Execution Vulnerability
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 16 Mar 2008 12:46:37 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
CiscoWorks Internetwork Performance Monitor Command Execution
Vulnerability
------------------------------------------------------------------------
SUMMARY
CiscoWorks Internetwork Performance Monitor (IPM) version 2.6 for Sun
Solaris and Microsoft Windows operating systems contains a vulnerability
that allows remote, unauthenticated users to execute arbitrary commands.
There are no workarounds for this vulnerability. Cisco has made free
software available to address this issue for affected customers.
DETAILS
Vulnerable Systems:
* IPM version 2.6 for Solaris and Windows
Immune Systems:
* PM versions 2.5 and earlier
* IPM version 4.0
CiscoWorks IPM is a troubleshooting application that gauges network
response time and availability. It is available as a component within the
CiscoWorks LAN Management Solution (LMS) bundle. IPM version 2.6 for
Solaris and Windows contains a process that causes a command shell to
automatically be bound to a randomly selected TCP port. Remote,
unauthenticated users are able to connect to the open port and execute
arbitrary commands with casuser privileges on Solaris systems and with
SYSTEM privileges on Windows systems. This vulnerability is documented in
CVE-2008-1157 and Cisco Bug ID CSCsj06260 ( registered customers only) .
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1157>
CVE-2008-1157
Impact:
Successful exploitation of the vulnerability may result in the ability to
execute arbitrary commands with the non-privileged casuser user account on
Solaris systems and with full administrative SYSTEM privileges on Windows
systems.
ADDITIONAL INFORMATION
The information has been provided by <mailto:psirt@xxxxxxxxx> Cisco
Systems Product Security Incident Response Team.
The original article can be found at:
<http://www.cisco.com/warp/public/707/cisco-sa-20080313-ipm.shtml>
http://www.cisco.com/warp/public/707/cisco-sa-20080313-ipm.shtml
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NEWS] IBM Informix Dynamic Server Authentication Password Stack Overflow Vulnerability
- Next by Date: [NEWS] Java Web Start Encoding Stack Buffer Overflow
- Previous by thread: [NEWS] IBM Informix Dynamic Server Authentication Password Stack Overflow Vulnerability
- Next by thread: [NEWS] Java Web Start Encoding Stack Buffer Overflow
- Index(es):
Relevant Pages
- [NT] Microsoft Windows WMF Triggerable Kernel Design Error DoS Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Windows WMF Triggerable
Kernel Design Error DoS Vulnerability ... (Securiteam) - [NT] Vulnerability in Windows Shell Allows Remote Code Execution (MS05-016)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... A remote code execution vulnerability
exists in the Windows Shell because ... * Microsoft Windows XP Service Pack 1 and
Microsoft Windows XP Service ... (Securiteam) - [UNIX] Trend Micro VirusWall Buffer Overflow in VSAPI Library
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... buffer overflow vulnerability
in VSAPI library allows arbitrary code ... is called "vscan" which is set suid root by
default. ... permissions and thus granted all local users the privilege to execute the
... (Securiteam) - [EXPL] InterVations NaviCopa HTTP Server Buffer Overflow (Exploit)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... the latest release of InterVations
NaviCopa HTTP server 2.01. ... exploitation of this vulnerability allows an attacker
to execute arbitrary ... By default (Windows English version), ... (Securiteam) - [UNIX] SCO Multiple Local Buffer Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Local exploitation of a buffer
overflow vulnerability in the ppp binary, ... allows attackers to gain root privileges.
... (Securiteam)