vendor:
UniData
by:
Luigi Auriemma
7,5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: UniData
Affected Version From: 7.2.7.3806
Affected Version To: 7.2.7.3806
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
UniData Denial of Service Vulnerabilities
The unirpc service listening on port 31438 is affected by various Denial of Service vulnerabilities regarding the access of invalid zones of memory. Although the first vulnerability is a memory corruption problem where the program calls recv() using a heap buffer and a huge amount of data to copy (like 0x7fffffe8, decided by the attacker) in my tests it didn't result exploitable.
Mitigation:
No fix.