vendor:
NetSupport Manager Agent
by:
Luca Carettoni
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: NetSupport Manager Agent
Affected Version From: NetSupport Manager for Linux v11.00 and likely all previous, NetSupport Manager for Solaris v9.50 and likely all previous, NetSupport Manager for Mac OS X v11.00 and likely all previous
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Solaris, Mac OS X
2010
NetSupport Manager Agent Remote Buffer Overflow
NetSupport Manager Agent Remote Buffer Overflow is a vulnerability that affects the NetSupport Manager for Linux v11.00 and likely all previous, NetSupport Manager for Solaris v9.50 and likely all previous, NetSupport Manager for Mac OS X v11.00 and likely all previous. This exploit has been tested against NetSupport Manager Linux agent v10.50.0 and NetSupport Manager Linux agent v11.0.0. It is still unpatched as far as the author knows. The exploit uses a payload of 'A' characters followed by a return address and a NOP sled, followed by a shellcode.
Mitigation:
Update to the latest version of NetSupport Manager.