[VulnWatch] BakBone NetVault 6.x/7.x multiples vulnerabilities + exploit

class101_at_HAT-SQUAD.com
Date: 04/13/05

  • Next message: NGSSoftware Insight Security Research: "[VulnWatch] Windows kernel overflow fixed"
    To: "Full-Disclosure" <Full-Disclosure@lists.grok.org.uk>, <vulnwatch@vulnwatch.org>
    Date: Wed, 13 Apr 2005 15:26:00 +0200
    
    

    As a recall, there is one month, the Hat-Squad found 2 security holes
    affecting BakBone NetVault all versions.
    And as far as I know (sorry if I missed the hotfix), there is still no patch
    available .....
    We will re-publish this warning as long as (each month) there is no fix.
    Some temp. countermeasures are available in both *.pdf

    BakBone NetVault 6.x/7.x Remote Heap Buffer Overflow advisory

    class101.org/netv-remhbof.pdf

    BakBone NetVault 6.x/7.x Remote Heap Buffer Overflow exploit

    class101.org/36/55/op.php

    BakBone NetVault 6.x/7.x Local Stack Buffer Overflow advisory

    class101.org/netv-locsbof.pdf

    BakBone NetVault 6.x/7.x Local Stack Buffer Overflow exploit

    class101.org/36/55/op.php

    -------------------------------------------------------------
    class101
    Jr. Researcher
    Hat-Squad.com
    -------------------------------------------------------------


  • Next message: NGSSoftware Insight Security Research: "[VulnWatch] Windows kernel overflow fixed"

    Relevant Pages

    • Re: [Full-disclosure] BakBone NetVault last warning
      ... have been also surprised to not see the word "security" in their open ... > high security risks still UNPATCHED for BakBone NetVault 6.x/7.x ... > BakBone NetVault 6.x/7.x Remote Heap Buffer Overflow advisory ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: [Full-disclosure] BakBone NetVault last warning
      ... "when a man such as you reports a security hole we can not put all works ... What kind of man must you be to make them say "yes: we are fixing it". ... >high security risks still UNPATCHED for BakBone NetVault 6.x/7.x all ... >BakBone NetVault 6.x/7.x Remote Heap Buffer Overflow advisory ...
      (Full-Disclosure)
    • Re: [Full-disclosure] BakBone NetVault last warning
      ... > high security risks still UNPATCHED for BakBone NetVault 6.x/7.x ... > BakBone NetVault 6.x/7.x Remote Heap Buffer Overflow advisory ...
      (Full-Disclosure)
    • [VulnWatch] Re: [Full-disclosure] BakBone NetVault last warning
      ... > high security risks still UNPATCHED for BakBone NetVault 6.x/7.x ... > BakBone NetVault 6.x/7.x Remote Heap Buffer Overflow advisory ...
      (VulnWatch)
    • BakBone NetVault last warning
      ... high security risks still UNPATCHED for BakBone NetVault 6.x/7.x all ... BakBone NetVault 6.x/7.x Remote Heap Buffer Overflow advisory ...
      (Bugtraq)