vendor:
Disk Pulse Server
by:
xsploited security
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Disk Pulse Server
Affected Version From: v2.2.34
Affected Version To: v2.2.34
Patch Exists: NO
Related CWE:
CPE: diskpulse_server:2.2.34
Platforms Tested: Windows XP SP3
2010
Disk Pulse Server v2.2.34 Remote Buffer Overflow Exploit
A vulnerability exists in the way Disk Pulse Server v2.2.34 processes a remote client's "GetServerInfo" request. The vulnerability is caused due to a boundary error in libpal.dll when handling network messages and can be exploited to cause a stack-based buffer overflow via a specially crafted packet sent to TCP port 9120.
Mitigation:
Patch or update to a version that is not vulnerable.