vendor:
NET-i ware
by:
Luigi Auriemma
8,8
CVSS
HIGH
Endless loop, Code execution and Stack overflow
119, 20, 787
CWE
Product Name: NET-i ware
Affected Version From: 1.0
Affected Version To: 1.37
Patch Exists: Yes
Related CWE: N/A
CPE: a:samsung:net-i_ware
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Endless loop in remote services, Code execution in ConnectDDNS ActiveX and Stack overflow in BackupToAvi ActiveX
All the NET-i ware services are affected by an endless loop caused by the wrong handling of negative 32bit size fields. Code execution vulnerability in the ConnectDDNS method used by the following ActiveX components: EEDBA32E-5C2D-48f1-A58E-0AAB0BC230E3 and 17A7F731-C9EC-461C-B813-2F42A1BB58EB. Stack overflow in the BackupToAvi method used by the same ActiveX components, triggered by a too long string passed to the BackupToAvi method.
Mitigation:
Update to the latest version of NET-i ware